Red Hat Security Advisory: OpenShift Container Platform 4.14.37 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-7387 — openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy CVE-2024-45496 — openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift
🎯 Affected products9
- Red Hat OpenShift Container Platform 4.14
- openshift4/ose-docker-builder@sha256:51fa75886567b695d7d89307a7f54685506d4696c4791920291f2724b7627545_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-docker-builder@sha256:65285f8fb16b89b2cc83aef9a2d552ff4307878e21f74cafe4d02011074b7e26_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-docker-builder@sha256:e102a12ffbb2576ea4c24bdfff29ddd024c182cf9e0dd6f2187991ffbcff0d70_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-docker-builder@sha256:efe984d8d96a5e0bcb9a8c550f27c8548cca5da437bfa60d08675e045a67c646_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-openshift-controller-manager-rhel8@sha256:0ba307b99ff3449681dff60de29910a1d8d83f7e9b127704bc6054731fc55ee3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-openshift-controller-manager-rhel8@sha256:3ac3c7fde9327c2c5b6bea5437fcf423460dde2fa3114fef6de04da1e3f6ac55_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-openshift-controller-manager-rhel8@sha256:76fb1603ce549e454aa26c36a51306a2a05bfe49333824c0c8223fcb296ed3b6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-openshift-controller-manager-rhel8@sha256:c854cb4740778b1f85718c104f7c773df36f712c1adf4806b034811a74ed9d55_s390x as a component of Red Hat OpenShift Container Platform 4.14
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:14e6ba3975e6c73b659fa55af25084b20ab38a543772ca70e184b903db73092b (For s390x architecture) The image digest is sha256:46442c04cb44a30b0de3bcfbd528eb2ee951bde4997d293f0dc2254e9d80c08a (For ppc64le architecture) The image digest is sha256:bfce075584c08b174fce03aec8fbc25ee651891f941102f9e94294b0cd689502 (For aarch64 architecture) The image digest is sha256:ea16a3d17df211406420d897068cd14d18347bf26321393fb2f7a57bbc9dcf0e All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" build strategy on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" and “Source” build strategies on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:6689
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308661
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6689.json