RHSA-2020:5635MediumCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.7.0 extras and security update

Published
February 24, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash CVE-2020-24750 — jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation

🎯 Affected products130

  • Red Hat OpenShift Container Platform 4.7
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:1e0a2fc1d5bb8926f88a60c56a1ded8c910b39af2e7b29ffff467adce5c866d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:43c11bb94d95b58b07fede96fe96d3c292904f85b6f13a684950430f803469d3_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:89beb57fbc3b672f4700682cac91779f4e91208d7423b3c0c4e013711d41a0bc_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/network-tools-rhel8@sha256:2964648ed59e02e5852595c30bcf13dd57c1bbc9b5e443d045cc217ecadb471f_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/network-tools-rhel8@sha256:7d7d7a143af5ab70880d83625e176e5140ff0f57675c2553ba04a9b3b2bfafd8_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/network-tools-rhel8@sha256:7da622d049e86ce9438a0885ffd6139e4442b5de75227e017c5c343e8bca1759_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-ansible-operator@sha256:0f107732d01c659f11c881b3358c972d164b8a00ee8b9d3c51da5f293dc2f89f_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-ansible-operator@sha256:1ddcf832543fc93d2c230eaf8a8de01491d00abfeda8b6671be62dd498445740_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-ansible-operator@sha256:4d82ee44b0b8fb72b043aaadd8a3e26c521a05917b2c96df6eea87b29c521b85_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-capacity@sha256:1120ce10b82eb1818b6c8e21c968fa16ffea8679e2d3336ccf71b8986eb57cfe_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-capacity@sha256:2457d23d6f280e15db9e95080a321ec371e0376573b40472bbf186b221e5f27c_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-capacity@sha256:86a67c3f4e289074981c2d5801b7476518a11c275c4faf7d3a687668d8846d45_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:534bdca3071ffef9772bfbb4886d46c4c7bcd5239063d5677c84cc80c4a460de_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:6820ccded527954d54e1097b8aa4687cc2c6252fb5d8e85014d4ac215f812103_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-kube-descheduler-operator@sha256:8ef62c75495b3fba9699f281f525dafc98b45cab8b0e9005e1857ce2bedb0e57_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:534bdca3071ffef9772bfbb4886d46c4c7bcd5239063d5677c84cc80c4a460de_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:6820ccded527954d54e1097b8aa4687cc2c6252fb5d8e85014d4ac215f812103_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:8ef62c75495b3fba9699f281f525dafc98b45cab8b0e9005e1857ce2bedb0e57_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-nfd-operator@sha256:3eb1a43c7749c7d1b3f263de5b399c3b004d3f7abf61b2db4b42817f67ee7256_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-nfd-operator@sha256:52a4b6ccdfcf49083a4e9932006416f6062bdfe973f3847369c0a686b72a78dd_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-cluster-nfd-operator@sha256:61cf64ac93fa816fd847b6b77e1e7af7ef371cd9c22b5120a977774d68a38117_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:43d5a922b10e5046606e446cbd4ab9fd6ec1d392111900f51d5808419378b1a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:d657a06df47a338ba52eb486a828d98d32fbee12ddd32400fcefff2a78bee457_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:dbebea9c551f515dee77b02ac123d925388d7bb82a8a416f0e479b2d74ad933e_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-clusterresourceoverride-rhel8@sha256:4b0c62dcf30b6eb4dde8dfc64170a12c1b032b98c5a88e73f8ff51aef1abe81c_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-clusterresourceoverride-rhel8@sha256:8f199f1bdc20bf406cd3feff6e145d68dcb4dfe34fa7869e9d08f2472f850eb1_amd64 as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-clusterresourceoverride-rhel8@sha256:d23a6fbe3bc7527e44456ba9f7ba4366029be4bb600438dd3fc8e73518560679_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-descheduler@sha256:0ab67def3a8f691826813c8ebcc19818ac6c4f7cf3e596361726ffad79ed9865_ppc64le as a component of Red Hat OpenShift Container Platform 4.7
  • openshift4/ose-descheduler@sha256:9610ec562e4cb65e71deaf8a3a7b0b04f386db808673deb1fda32a9eb6a1eba0_s390x as a component of Red Hat OpenShift Container Platform 4.7
  • +100 more not shown

✅ Remediation

For OpenShift Container Platform 4.7 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.7/updating/updating-cluster-cli.html. Workaround: The following conditions are needed for an exploit, we recommend avoiding all if possible: * Deserialization from sources you do not control * `enableDefaultTyping()` * `@JsonTypeInfo using `id.CLASS` or `id.MINIMAL_CLASS` * avoid com.pastdev.httpcomponents in the classpath

🔗 References (22)