Red Hat Security Advisory: OpenShift Container Platform 4.16.13 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-7387 — openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-45496 — openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift
🎯 Affected products9
- Red Hat OpenShift Container Platform 4.16
- openshift4/ose-docker-builder-rhel9@sha256:99c52758c584eeaac4706a7d4ff747813600993375233a3ae2f1c0f9597c4a25_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-docker-builder-rhel9@sha256:9b22c04ee841fa893614b657dd09b09eab91337d6fa19545bceab3ec702675d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-docker-builder-rhel9@sha256:ad78a36dbc026f3afa72a89e62b9f9532f3af886504289e98647a51dd79dfdb9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-docker-builder-rhel9@sha256:ebce8b61e7b646e44f9d2b153f6d5e9896813a4124613b6bac58c4c21fb2ce66_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-openshift-controller-manager-rhel9@sha256:4fe3b83616617915c53da7bd17845e0ea043537eacbe85d2c73463c190db8a07_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-openshift-controller-manager-rhel9@sha256:bbfa150a26c337dc8f6bbd828ff3840295b1b5fbc2087ee25f34eb4e7c762a8e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-openshift-controller-manager-rhel9@sha256:e4b0d90085ef656f9cb84f90727570d4b3716136ff9c1f597b8e354bdd922951_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-openshift-controller-manager-rhel9@sha256:ecc25980c2629702c937e0d8d6cdb724988bd7db05cabbfae342186dffa43371_arm64 as a component of Red Hat OpenShift Container Platform 4.16
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:6078cb4ae197b5b0c526910363b8aff540343bfac62ecb1ead9e068d541da27b (For s390x architecture) The image digest is sha256:5b286b07b5267aa96af112f6420444d91c529456b7dc7e15d49ab4ef89ca9713 (For ppc64le architecture) The image digest is sha256:6c6b61c7890d49346e653b117c46f74171b2a65ce18edf11afa331e115ff392d (For aarch64 architecture) The image digest is sha256:9d2928127d6a440a8931b4a0c6f565cb490338804e920f4493fb7ce875884baa All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" build strategy on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" and “Source” build strategies on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:6687
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308661
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6687.json