Red Hat Security Advisory: OpenShift Container Platform 4.15.38 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2024-6508 — openshift-console: OAuth2 insufficient state parameter entropy CVE-2024-7409 — QEMU: Denial of Service via Improper Synchronization in QEMU NBD Server During Socket Closure CVE-2024-47875 — dompurify: nesting-based mutation XSS vulnerability
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:2f18aacc4b0e50ce4b3168eb96062838be4b8b9a54172208d093bebce6239deb_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:6349f6e5f44faef861d9723d63e010c96f192068569814709aa8f09c55054f6f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:9a09de4a6d3a5cd08961ac6f2fcbcdfe2cbb2c37fe50711e4b49bd78c7406c96_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:9fa6742ee51a96b8cf0ff306eecb5c0e6870ecfaf9d2899d6c7bd383b8051db3_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:34ccbd682067e731e2fa7b7ca5f6ca490ef11c2b654ae1358fb480bed6a5ba3b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:9accf7f7c6f51d406499c9a1e3192fd2b4f3726a10ed0f56af7e08d6e9e518db_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:b76a984a6b965729c6b625dd1bb1a11a99d0f8586c3b7042bd062e4647b0e59e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:c9a8989efd8801eb07b68d27f8a9aa0c143b1f4aef6f80e8a30b65b80900be4a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:1df32cf7d0948eaee2944b55d6c5c1d12bb06949f6d16482a63e034b07109456_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:487ff5c9bab994956790a74805be1e4ebd88588765f3bba443a1fac5ece3d2d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:610a0d8a6a44050786d5168839fb72ca7ba402022d816a489a1a6d51ff7947c3_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:bae4f4c8f1884b4933df294c9243b2cea722fbdae660dad5b107fc5dfecc40a2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:10f1b0cd39f8dfbf2ec91841214a4fe567fedb311dd62ac7378b0099d43af7c0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:29609e1d2e612624e7885cb77d0eaa9c75ae5a1f13986bfdf6e5839163fb7a54_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:990162eaeb4c1c2a57d6a0b5d8e924f3bebeceb3382895da3e9a6510067994a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:9c82b938f68f6d53dc5922735c5c92374c65c3763872f06bc0f870bf960e77e4_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:10565cf308463c1f074fdae91a11f4ff83cefb1bf07a1a94c97723df51abd457_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:69e762d30ad88d722f6272e120df47fd2cad452c5c22866652af740f91334b6e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:cc8710b75ce0a24cedaea2588de1da014b73c41b89051f2b7245ea678b9fe4ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:d5c82472acbe338d1a27dc853eaf47979ffec3622366a48487cc8b696c2d0088_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:00fd5b927d93d85783ef32c98916cf4f27804b2f524fa5e48f8f5be84dfd50a6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:0da06fe3e3d89dad6a3f68b2ccd6665b0dd5befe6e73d7adfe619ed5524cd135_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:301c59fcdf3acf0d894cd99d73059c97efbaac6729f15ce9e351744a3ac8c90b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:a8affb72128463b35d839e3e12eccdca4066672c969b362bb02855b9cd34f952_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:2314f70b625693dce0e151cc75e2a5bd2e74857e1e73e539bfc72d4908d97e1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:a00927809eef6316bec078189f2378bfe08615e58dd1695030146815bd0b5f71_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:c2c15ef8d0e37037c9734720d0df851efb1b82da69f23dae3b1d8cd3f0edec76_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:fffe7b1ee512933d1f8f8dfe7ff788816e3412b671657de549a093d270679267_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:487e09f41b960ca14a1ca14f76085a35f075f55222b8a2c08e974d79d5cf99d9_s390x as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:bcc1b1803a49b9ac876a7dd950138439aacb81f070a64ae0a2f16e01594b7291 (For s390x architecture) The image digest is sha256:a30a4b62995d123fd352ca1676847414e55c7728b23655435d5fce4227d6a486 (For ppc64le architecture) The image digest is sha256:f8d27d42b75c58ae8bf89820ee089893fdeeebfe6b80dd0481994da9e9c6c7a0 (For aarch64 architecture) The image digest is sha256:16f31d7b926ce2bdae0e4bf911fffb68d30b449870c99c6411c9ecc0648d7b91 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2024:8991
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302487
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2318052
- externalhttps://issues.redhat.com/browse/OCPBUGS-30207
- externalhttps://issues.redhat.com/browse/OCPBUGS-34510
- externalhttps://issues.redhat.com/browse/OCPBUGS-42110
- externalhttps://issues.redhat.com/browse/OCPBUGS-42865
- externalhttps://issues.redhat.com/browse/OCPBUGS-42930
- externalhttps://issues.redhat.com/browse/OCPBUGS-43268
- externalhttps://issues.redhat.com/browse/OCPBUGS-43575
- externalhttps://issues.redhat.com/browse/OCPBUGS-43582
- externalhttps://issues.redhat.com/browse/OCPBUGS-43646
- externalhttps://issues.redhat.com/browse/OCPBUGS-43656
- externalhttps://issues.redhat.com/browse/OCPBUGS-43855
- externalhttps://issues.redhat.com/browse/OCPBUGS-43876
- externalhttps://issues.redhat.com/browse/OCPBUGS-43918
- externalhttps://issues.redhat.com/browse/OCPBUGS-44035
- externalhttps://issues.redhat.com/browse/OCPBUGS-44201
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8991.json