Red Hat Security Advisory: OpenShift Container Platform 4.13.50 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-7387 — openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy CVE-2024-45496 — openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift
🎯 Affected products9
- Red Hat OpenShift Container Platform 4.13
- openshift4/ose-docker-builder@sha256:183357f5814e25324e353ffde2d29080ba70aa627a2b92610a8feb37cd058fff_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-docker-builder@sha256:7530bc95adc756aecc958d3ade9e657cb39c3ed0351fe803ccd1dcd8a5e748af_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-docker-builder@sha256:8c03f5c4a50133032837b0e682c11b3ace5b7d85b684ae151cc704e6f2cac0a2_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-docker-builder@sha256:f5399816f46feb8918f1d162ca82beaf134bbbf5cf254fc6b5ddea5a30dd33f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-openshift-controller-manager-rhel8@sha256:51f1087f2c892ac2490676ec4f94da0430134c541eb4485c44662b58052ec2ba_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-openshift-controller-manager-rhel8@sha256:6efd236d672c18eec48a6a2744e87e124eab7accdaf7cf39d26217a402b3fcf5_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-openshift-controller-manager-rhel8@sha256:bdde93e036c83ebeb573c8788d09569e989b87c22a768476e8cefc587071d948_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-openshift-controller-manager-rhel8@sha256:de7260141fff0f5202924b52a24e5b4e268ca777de75fb5b2d49e82e9537dabc_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:6afb11e1cac46fd26476ca134072937115256b9c6360f7a1cd1812992c065f02 (For s390x architecture) The image digest is sha256:1bdaf80b51a47cd545a4aa2c7282ab2093574fbee2f770acf10a19de7ca5daea (For ppc64le architecture) The image digest is sha256:9033dfb9cdc34eb73d50dfa4d5f329061ab232238a04993fb2baf19e42b7073a (For aarch64 architecture) The image digest is sha256:fda846b80f2dc96941f157c9db383a37d87b4f4cfcb9e9dd2fcd29972b239200 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" build strategy on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" and “Source” build strategies on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:6691
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308661
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6691.json