RHSA-2021:1429LowCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.6.27 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-25649 — jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)
🎯 Affected products133
- Red Hat OpenShift Container Platform 4.6
- openshift4/driver-toolkit-rhel8@sha256:0ce00fcce0726c816928d9c63e122be31fb7e825af384bc9bc6c8be9ebd7965b_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/driver-toolkit-rhel8@sha256:2f81a9d6098945caf43e4f194b10e20287fb9c9a6f946cf9b545e5bcc8b97480_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/driver-toolkit-rhel8@sha256:63784975dfa8c3df07e3d4c2738d705cd8914ac2476a156e05e11bb0504c1159_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-ansible-operator@sha256:128ed480e58d7bc9e5b46e62d1fe51efc8e2db96f1d74631655f46e8185a8f59_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-ansible-operator@sha256:79a98ec9947f40458af412feaec4bb6e186defeaed9b8706346717597c43b5db_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-ansible-operator@sha256:f3fe46f688e98aea542c38c40c16c97b45d1311260f3c87ddcab2ad707007d7f_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-capacity@sha256:56a406c60f5cd416fe54b5c13d6ed3e34bc18892c54634f8252e4fb057e7b2fe_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-capacity@sha256:756fc9b46141b06533e4d1f629749eb3077d1b2aa78d941550be1fefdf836e27_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-capacity@sha256:9c158955097c3e2102a0224558ad9a0007e15a63f9821951f60eec82ccca5904_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-kube-descheduler-operator@sha256:1d1d9e1febf6734249627f898c1d4e049c7b23b1f79905d4fae333dde6d49a70_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-kube-descheduler-operator@sha256:7e663a120f1eba8d5ae7614c6d5e5b6f110ad17b954cadd876dedd7a77d1afc9_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-kube-descheduler-operator@sha256:e8ab3f1b4efaaee4c048768a6e7d949071b999ad75965dac4cc51cad01eed08e_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:1d1d9e1febf6734249627f898c1d4e049c7b23b1f79905d4fae333dde6d49a70_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:7e663a120f1eba8d5ae7614c6d5e5b6f110ad17b954cadd876dedd7a77d1afc9_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:e8ab3f1b4efaaee4c048768a6e7d949071b999ad75965dac4cc51cad01eed08e_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-logging-operator@sha256:2430d6dac65f772dcc5605693bc35a178f2a989bc5b8de21a1efe3b7e5954048_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-logging-operator@sha256:7eb28beb3b0694b5e916f5e71b5939c47aaed9db4ac98cb0b34c56511ecb7773_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-logging-operator@sha256:dedc9ced6cadf8eb355b4dee118456053c44151f78489393230710fff5360c9f_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-nfd-operator@sha256:739ca97189a526f9d8db3ad6ad36bbf45d1da81f8f7b6d401eef1aadeb6fae16_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-nfd-operator@sha256:b9782c0f9549a7abae61d81135d49cf35bc46c17a2eea73612872c0de8c42a85_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-cluster-nfd-operator@sha256:e9c400cfeab1c9878ae537f56c1f11ac646534e89493fb7cc75425cfec639397_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:132d7c2eebee9023a76d87fd4c4520e24fad3b0ff9db3c30bceaa56a19493354_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:26fa1be6c37710d08c484f6f0f38f2aa0b339f348b422bdc3e2c333850591edf_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:5da9f9d88bd70346f28553d703d6423907a40a2a748d7e9a091450d6a18e12b5_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-clusterresourceoverride-rhel8@sha256:1dc93a8fa2b9d533ed15f02d63d15715113f0e0ccffd33d52bd3c8c2502ddc69_s390x as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-clusterresourceoverride-rhel8@sha256:8214214ef887ca8ee363a438cbff051460b3a7192ff953f09a8220b71dc4736e_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-clusterresourceoverride-rhel8@sha256:e22a9f89ea07245c5c778b93555dd66d5fcf2e467f0a4090d3c2872cb4d14e15_amd64 as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-descheduler@sha256:35d26a7ba6aa006ebe3469e2473f19de4e065b4b13ea87796fda8ec9b8e23916_ppc64le as a component of Red Hat OpenShift Container Platform 4.6
- openshift4/ose-descheduler@sha256:63d66b8e1644365d4f7c3576d0b61cc0712bb08ea30e1fac76a5317f1b65cf53_s390x as a component of Red Hat OpenShift Container Platform 4.6
- +103 more not shown
✅ Remediation
For OpenShift Container Platform 4.6 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.6/updating/updating-cluster-cli.html Workaround: There is currently no known mitigation for this flaw.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2021:1429
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1887664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1941768
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1954163
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1429.json