RHSA-2019:2817MediumCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 3.11 security update

Published
September 23, 2019
Last Modified
August 15, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-10214 — containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure

🎯 Affected products6

  • Red Hat OpenShift Container Platform 3.11
  • cri-o-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • cri-o-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • cri-o-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • cri-o-debuginfo-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • cri-o-debuginfo-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11

✅ Remediation

See the following documentation, which will be updated shortly for release 3.11.146, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html

🔗 References (4)