Red Hat Security Advisory: OpenShift Container Platform 4.17.1 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2023-3462 — Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-6345 — pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools CVE-2024-6508 — openshift-console: OAuth2 insufficient state parameter entropy CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-27289 — pgx: SQL Injection via Line Comment Creation CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1bcdd2ed3c97e255550f852cca85e256640dddc495a1160ac0b7d9e4abffe262_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:1f7fe2f732e8a986ce941f255022cff97093386e1a2060c14ea9c5d36f0f8a26_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:24f4788e924ee1f48053267587d369f0d6a4a7e190f699439533dae6e56cac5d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/aws-kms-encryption-provider-rhel9@sha256:72c9ec6965ceb5590cb504ca9374ad44a61547566a4f7ce0b84a40dbd26966c7_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:0c674c6cfb3981faf177280e34940cd080f02a89cefe7bbb0ab1fce797dc4a37_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:e587119d7c08cd70c7754111df5cf0dab35a8ab6734d8323fe6c5a434982811a_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:e92c1ddecfbb1cea9949c6c9180ea74073fa3276c963e376a1807fc1266af605_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/azure-kms-encryption-provider-rhel9@sha256:ebb0f2c7e56256a1424357e0240e3a21850c24130efb4377c8b6f78a04f62f93_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:5fde735867972703e6d902ee7a244f5065c62f984001a890002a8c11bad0f20f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:8aab19cd7e2367af679951429ba14dfcdc6bb3cc7acf33e12904e675c58f3b81_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:c04b64037ba3e1e16670fd92198a4148710d7feed91a4dfe40869a0c6ca1a4d9_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/cloud-network-config-controller-rhel9@sha256:c6eacc9a5fbc7fd44a8c3a778637d2c2d0203740097cdae7a3950ff0c834e223_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:2fa364eba2aac8db5e277bf5b54eea490fa479ac6766cfa2c1d87d94c7030e7f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:3b4f1b385de3d196c88978017a8d2033ccc9a23fbef6021b44d376179562d165_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:8d294263e411fc0269c0e1f9ff2b1399f7ba0966ab394c85ddc5590bc8d95564_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/container-networking-plugins-microshift-rhel9@sha256:abd8a7135673758866f2e37179b29c00a2fd5eebaae164a7a812d6ab4eea17ed_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:1aec77ce5af7ead269492d94955582ce551b65316ce4df533914e55fa9bf8683_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:34af2f3655846c99687463e62d4f82fb8d5ab5bacf2b1f122080f432d762c2a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:b6efaad946fdb8f37c875435e416f0061523de6d82153a11654aeb60c162c60a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/driver-toolkit-rhel9@sha256:cf21c61440da418e85b4de73aaccdcb639b37322d048a27dc1705b65c37ef71d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:971ce45d8d0167b97dc415197ac98f849a46cec6267c140de07853cfac3d86f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:b88152afdae36385b3a0c77cd74b000b83aded51650f9780db3ec5b0879ade41_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:b98b0b8c5f5d3d15dfa6ba1863c51d08a9c09facf4cb0e8c76c133cf1542cb0d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/egress-router-cni-rhel9@sha256:eb6233336f6ada99abe92ecd11074344bac978cec99034a164a742ace0b593d9_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:7a5c3ef236c568960ca4d2ed77e94bda68bb207341693221a0dbdc9141d2a2f4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:850370aba1024e7205991dc59fa81003b14d69448d823e891f31b385c09f73c8_s390x as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:af89d97f426f67916866df0fd661e5ebb5e5e288130c24c2b768886d5b51f1b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/frr-rhel9@sha256:eaea20567b19e6f0a1738aa08c8a47c3875e87e2b200529bcf607b1a68476107_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- openshift4/kube-metrics-server-rhel9@sha256:1bb30cb0abc725a5fdd19b9a719510f5ece9fd702f61d547bca5e12ff6b4c339_s390x as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e16ac60ac6971e5b6f89c1d818f5ae711c0d63ad6a6a26ffe795c738e8cc4dde (For s390x architecture) The image digest is sha256:c3372900c1b249fc1fa017db9ddcfa2b97a71a358e8d377481e0ca04a9d121d3 (For ppc64le architecture) The image digest is sha256:fec4a60f96ad4c29ff2d4401fa079c5b1e0af05b0914cae2b8d29ff026654d95 (For aarch64 architecture) The image digest is sha256:62b77793b08477b7c785ac0fab76f919bed8cf31c1bf4678da4df03b8c2a7a58 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: A possible mitigation is to not use the simple protocol or do not place a minus directly before a placeholder.
🔗 References (109)
- selfhttps://access.redhat.com/errata/RHSA-2024:7922
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268465
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://issues.redhat.com/browse/OCPBUGS-30950
- externalhttps://issues.redhat.com/browse/OCPBUGS-33815
- externalhttps://issues.redhat.com/browse/OCPBUGS-33834
- externalhttps://issues.redhat.com/browse/OCPBUGS-33899
- externalhttps://issues.redhat.com/browse/OCPBUGS-34034
- externalhttps://issues.redhat.com/browse/OCPBUGS-34073
- externalhttps://issues.redhat.com/browse/OCPBUGS-34134
- externalhttps://issues.redhat.com/browse/OCPBUGS-34217
- externalhttps://issues.redhat.com/browse/OCPBUGS-34285
- externalhttps://issues.redhat.com/browse/OCPBUGS-34314
- externalhttps://issues.redhat.com/browse/OCPBUGS-34643
- externalhttps://issues.redhat.com/browse/OCPBUGS-35430
- externalhttps://issues.redhat.com/browse/OCPBUGS-35868
- externalhttps://issues.redhat.com/browse/OCPBUGS-36213
- externalhttps://issues.redhat.com/browse/OCPBUGS-36680
- externalhttps://issues.redhat.com/browse/OCPBUGS-38240
- externalhttps://issues.redhat.com/browse/OCPBUGS-38379
- externalhttps://issues.redhat.com/browse/OCPBUGS-38457
- externalhttps://issues.redhat.com/browse/OCPBUGS-38462
- externalhttps://issues.redhat.com/browse/OCPBUGS-38471
- externalhttps://issues.redhat.com/browse/OCPBUGS-38563
- externalhttps://issues.redhat.com/browse/OCPBUGS-38574
- externalhttps://issues.redhat.com/browse/OCPBUGS-38760
- externalhttps://issues.redhat.com/browse/OCPBUGS-38770
- externalhttps://issues.redhat.com/browse/OCPBUGS-38784
- externalhttps://issues.redhat.com/browse/OCPBUGS-38927
- externalhttps://issues.redhat.com/browse/OCPBUGS-39013
- externalhttps://issues.redhat.com/browse/OCPBUGS-39071
- externalhttps://issues.redhat.com/browse/OCPBUGS-39091
- externalhttps://issues.redhat.com/browse/OCPBUGS-39120
- externalhttps://issues.redhat.com/browse/OCPBUGS-39124
- externalhttps://issues.redhat.com/browse/OCPBUGS-39286
- externalhttps://issues.redhat.com/browse/OCPBUGS-39390
- externalhttps://issues.redhat.com/browse/OCPBUGS-39409
- externalhttps://issues.redhat.com/browse/OCPBUGS-39414
- externalhttps://issues.redhat.com/browse/OCPBUGS-39601
- externalhttps://issues.redhat.com/browse/OCPBUGS-41255
- externalhttps://issues.redhat.com/browse/OCPBUGS-41341
- externalhttps://issues.redhat.com/browse/OCPBUGS-41357
- externalhttps://issues.redhat.com/browse/OCPBUGS-41376
- externalhttps://issues.redhat.com/browse/OCPBUGS-41576
- externalhttps://issues.redhat.com/browse/OCPBUGS-41622
- externalhttps://issues.redhat.com/browse/OCPBUGS-41685
- externalhttps://issues.redhat.com/browse/OCPBUGS-41686
- externalhttps://issues.redhat.com/browse/OCPBUGS-41817
- externalhttps://issues.redhat.com/browse/OCPBUGS-41893
- externalhttps://issues.redhat.com/browse/OCPBUGS-41908
- externalhttps://issues.redhat.com/browse/OCPBUGS-41914
- externalhttps://issues.redhat.com/browse/OCPBUGS-41933
- externalhttps://issues.redhat.com/browse/OCPBUGS-41941
- externalhttps://issues.redhat.com/browse/OCPBUGS-42006
- externalhttps://issues.redhat.com/browse/OCPBUGS-42007
- externalhttps://issues.redhat.com/browse/OCPBUGS-42008
- externalhttps://issues.redhat.com/browse/OCPBUGS-42019
- externalhttps://issues.redhat.com/browse/OCPBUGS-42060
- externalhttps://issues.redhat.com/browse/OCPBUGS-42066
- externalhttps://issues.redhat.com/browse/OCPBUGS-42081
- externalhttps://issues.redhat.com/browse/OCPBUGS-42098
- externalhttps://issues.redhat.com/browse/OCPBUGS-42116
- externalhttps://issues.redhat.com/browse/OCPBUGS-42126
- externalhttps://issues.redhat.com/browse/OCPBUGS-42131
- externalhttps://issues.redhat.com/browse/OCPBUGS-42142
- externalhttps://issues.redhat.com/browse/OCPBUGS-42164
- externalhttps://issues.redhat.com/browse/OCPBUGS-42200
- externalhttps://issues.redhat.com/browse/OCPBUGS-42223
- externalhttps://issues.redhat.com/browse/OCPBUGS-42232
- externalhttps://issues.redhat.com/browse/OCPBUGS-42248
- externalhttps://issues.redhat.com/browse/OCPBUGS-42256
- externalhttps://issues.redhat.com/browse/OCPBUGS-42261
- externalhttps://issues.redhat.com/browse/OCPBUGS-42277
- externalhttps://issues.redhat.com/browse/OCPBUGS-42296
- externalhttps://issues.redhat.com/browse/OCPBUGS-42323
- externalhttps://issues.redhat.com/browse/OCPBUGS-42336
- externalhttps://issues.redhat.com/browse/OCPBUGS-42357
- externalhttps://issues.redhat.com/browse/OCPBUGS-42362
- externalhttps://issues.redhat.com/browse/OCPBUGS-42380
- externalhttps://issues.redhat.com/browse/OCPBUGS-42394
- externalhttps://issues.redhat.com/browse/OCPBUGS-42410
- externalhttps://issues.redhat.com/browse/OCPBUGS-42421
- externalhttps://issues.redhat.com/browse/OCPBUGS-42483
- externalhttps://issues.redhat.com/browse/OCPBUGS-42580
- externalhttps://issues.redhat.com/browse/OCPBUGS-42581
- externalhttps://issues.redhat.com/browse/OCPBUGS-42582
- externalhttps://issues.redhat.com/browse/OCPBUGS-42585
- externalhttps://issues.redhat.com/browse/OCPBUGS-42606
- externalhttps://issues.redhat.com/browse/OCPBUGS-42612
- externalhttps://issues.redhat.com/browse/OCPBUGS-42622
- externalhttps://issues.redhat.com/browse/OCPBUGS-42677
- externalhttps://issues.redhat.com/browse/OCPBUGS-42678
- externalhttps://issues.redhat.com/browse/OCPBUGS-42681
- externalhttps://issues.redhat.com/browse/OCPBUGS-42699
- externalhttps://issues.redhat.com/browse/OCPBUGS-42714
- externalhttps://issues.redhat.com/browse/OCPBUGS-42721
- externalhttps://issues.redhat.com/browse/OCPBUGS-42786
- externalhttps://issues.redhat.com/browse/OCPBUGS-42812
- externalhttps://issues.redhat.com/browse/OCPBUGS-42814
- externalhttps://issues.redhat.com/browse/OCPBUGS-42853
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7922.json