RHSA-2024:5199MediumCVSS 6.0

Red Hat Security Advisory: OpenShift Container Platform 4.12.63 security and extras update

Published
August 19, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file

🎯 Affected products72

  • Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:7223d061d22f302dc85031b68884fefdc5b958570878f57d6c27a6a89fd9d15b_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift-tech-preview/metallb-rhel8@sha256:ad27c0b9b0204a8b9cb83b793833856f579b30d07ecf25b880fb47f05d05c485_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:bbb68498bf47794655cec2658a68647a80c591aef72723540803590974195a4a_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/frr-rhel8@sha256:d2691d12b3c543aad5a105053e42452d9529e2a7fb92f49522b92af1ced0c09a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:774f8ce1f8ccf207db66a6bd26e1fbf416c8b614a0ace8483674d6698f7f0508_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:7b3174af79cb53361cd66e76e2fff442f47d582aa55252acd119a36b817a7944_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:c27f4f863bec1bb34469cbd49bed4dec1591fc6fed51cae2dfbadecf494d0bac_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:c90b6a314f7e325f1ef8c7c14ce1e70f1697246a62d6674bc78404eef8b34fca_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8@sha256:7223d061d22f302dc85031b68884fefdc5b958570878f57d6c27a6a89fd9d15b_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8@sha256:ad27c0b9b0204a8b9cb83b793833856f579b30d07ecf25b880fb47f05d05c485_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-ansible-operator@sha256:33eb3e8677b3572ccf3c83a93026cc0d5f562224b2f78e04ad6f85593928c961_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-ansible-operator@sha256:4490100743716d73676e825967063d878a824acee5ad5cb340e677c1d1929b93_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:a437eef2136e447df8b1d7faa094352c1e8eeef0651788883482dc0ea60ef105_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:82b2cdc2dafbef35f46c62cec2efdaa3ccb567f6655ef545bcc55d051cbc75d3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cloud-event-proxy-rhel8@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cloud-event-proxy@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-capacity@sha256:54de015aac0607951dd04ec830af82c46d5afde9d861bd1182f91c74f79247ac_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-capacity@sha256:ddb01be63de7ea06936b72f5592a50b610be89fa895d043fcf79c60d3f9e0068_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:588297bb92af2580e32454d3efa288a1ac67dd48a6a49338cac1d779f9891f8a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:63d4b27c169da993597f5eaec2950c54c7021708b996cb220a1d91062c1ef354_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:588297bb92af2580e32454d3efa288a1ac67dd48a6a49338cac1d779f9891f8a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:63d4b27c169da993597f5eaec2950c54c7021708b996cb220a1d91062c1ef354_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-nfd-operator@sha256:435ec4fb18e43d0209e191660c91aa6eb8dc932fe5a0aea16ebd04c30d8fd9bb_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-nfd-operator@sha256:b84c2075a84ad8a7ea974045bfd7c88b1b4ed7c3a1db5364658f0e1537e97943_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:ac427fc5e250621eb40115e353509a680280ef3011b60d7c6c68a35c5678aa0d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:c605f3094258a25a20e5ee8fdef1ba186d0f164594349248c6f8e7b81666244b_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-clusterresourceoverride-rhel8@sha256:4b301eabc55306f6f8dc3a13facabd8d174ef28b6bf7b7343e3da4977566524f_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-clusterresourceoverride-rhel8@sha256:60b51fc60f6827bf8ee97d1f01c6a43906fb52036e9007e917131b57cb726662_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +42 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (4)