RHSA-2024:6705HighCVSS 9.9

Red Hat Security Advisory: OpenShift Container Platform 4.12.66 security update

Published
September 19, 2024
Last Modified
August 6, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-7387 — openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy CVE-2024-45496 — openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift

🎯 Affected products9

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-node-tuning-operator@sha256:c0f0c948e37742a9d22c5a51f4ae66da937ab4c8ee3cd5387041cb8ca943a8a6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-cluster-node-tuning-operator@sha256:fa325a5d0b1d7c1f493d1130795fc1ffc07eed9c2c5d9ef5b0bf82d909b0b1ce_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-docker-builder@sha256:47a70414f26155b2c54eea8973ec56ecc1b126bb86ad91bb09cdc0cb1e4f7008_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-docker-builder@sha256:c448e008f40cefb81cd75f99327b29876ab8eb1c4a55c0875490c7a08f3137cc_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-openshift-controller-manager-rhel8@sha256:0f2f6207add6a013df0f6cba651bd6c72e2e8cf5da49731bbf2e7291ed42ae79_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-openshift-controller-manager-rhel8@sha256:256ddb906f57aabaf53600b76ef0a11859ae74e064f18efee7676be1ab35af24_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • rhcos@sha256:0073bc154dd6646f10ed818536af17963f225424be852fb7def35d3e4181f4f6_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • rhcos@sha256:0073bc154dd6646f10ed818536af17963f225424be852fb7def35d3e4181f4f6_x86_64 as a component of Red Hat OpenShift Container Platform 4.12

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:1c522e4dd313e4e40af620bd08bef1f3d5518024d32107fa560617795ec0fadd (For s390x architecture) The image digest is sha256:0623cfc814cfe42740de33083f6dd739a88be6b4d6f2bddaedcf8fb8bca0d47e All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" build strategy on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html Workaround: Cluster admins can follow the instructions in "Securing Builds by Strategy" to block use of the "Docker" and “Source” build strategies on a cluster, or restrict the use to a set of highly trusted users, until the cluster is able to be upgraded. https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html

🔗 References (6)