Red Hat Security Advisory: OpenShift Container Platform 4.14.12 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-21708 — graphql-go: Denial of service via stack overflow panics CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products107
- Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:05bce6081ebd60260a2dc707855bb4c8c7597d84dc4cec8bf735a492bff2db9c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:242a3c6d3736a6827b16cf403eabbf5b12eb5dd766575a5606b5e48e230bea77_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:cfc7d5dc2069294c860fd779531513c23304e8a86f73f376016bb048e070b28d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:eb96c150d38135e5828626bbbff07164fa07a01a424ee433b5448f55dae5f0ed_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:392988b33b613ffe4981425bf96ebd72109398f4bd9297fdc74eaed6a0156fa6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:8242f96538e18eec148d5cf4d26c2f8bc837e0cb2d2b424183ea579803188fd2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:8a59164de78da22ad6934ecfe1f5aa18b81790c9aa4294e1769154d21c7a8c6c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:fe10793b6a5fe8bca87c08721730af057dc8df54bb32aeb53fb1bbdd443b0ec0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:84d480f2763a1db6756f4fe00e42876917672786e25fca03f44cfddaf28082a2_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:a87e6fdccf969eb1ffa5759542f7482bb76c0ee399111130d9a3579a9fa6fada_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b198aea08568e40e3f7f5329d2c1d3763bdb4bcc7a9f323b4704403d68656106_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:e7d7087f8c9e1640d6b741207f7b22cbf1ae820c263b0b9fd6bf96c41eeb1b86_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:c59197fd2b71316b51083010ed266b5dbd2337791c04d812497c716b914ed7d5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:7b0d07f44cab631ac47dc168e43d1716f1f332620706055574f9722c29e90296_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:fe6b1c8aea442792d49f21b76198467a70bda5f5b7430c42731c2f20eebc3a55_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:db4fa94339f96a72f989900d026f6782fc4032715d7c22e8f590202c3aba9bac_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:ec37033c2244931b1ca85fdd68a63047ad9f7fe6656d50dd311b604de83ef916_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:1a27f1946d3584056f73ff84d5a04294855d57dcfccc0487d9ff72f9de80ba62_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:3a82a2f0533422e928fced06677e53a331b94500f49a0230f5b7e652fd789003_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:819a069cd69a7e60e9e27d25ecc45648c9cca2dbf224856745be5cd27a586358_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cloud-credential-operator@sha256:fae618466660ee22e5e79c3f434d3f91bf589201dff6e2b65236f700e8021c41_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-machine-approver@sha256:7fbc684130d3167f7c7ffcdedc6a689b771b2c877e7e0f6de0f069be48e5f28c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-machine-approver@sha256:900f4859257659f4edcbc7fd162cf63ea1fd842a92c7d42d942178d43d379dd4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-machine-approver@sha256:b10af2df852f81b391898c2318cf66426aa64ba2930abfd49555b9722cb6125a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-machine-approver@sha256:c016ce76a990bf38c387ce52730e3cfc34e5f739ad5389816cdf9ff11278ed97_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-olm-operator-rhel8@sha256:9a07d7c5d06ba4adaa0a7889d23025aa63c46f6c5056129017172e8589f7ee5a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-olm-operator-rhel8@sha256:c208dbb5014ad7988e4b139c259c63693fd247a5eb6202666434645551461d86_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-olm-operator-rhel8@sha256:d80338391a783a1f831746b6905ad8558b9f671c8b898bc56a141d5bd84480fe_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cluster-olm-operator-rhel8@sha256:ea821cd31b9cea6048613fb6134af6b20c38893338c86e4effa43a98e342f38d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +77 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:671bc35e8fc2027d6f4c2c756d19909d83d55d1c591e8f9ea790ec8da744d171 (For s390x architecture) The image digest is sha256:641ac9df3fbc2575922e68cc2e3b0903d7d268faf6862777fca93ac7ed2fe82b (For ppc64le architecture) The image digest is sha256:ab24f08a86cb6715e3259153ab44820620d80f21c87781001289bc7ebe13cf02 (For aarch64 architecture) The image digest is sha256:7f3942d330660112a9220786bd2fb3015f05bda0354002f70cf5735e6386b93b All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2024:0735
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2045014
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-20180
- externalhttps://issues.redhat.com/browse/OCPBUGS-20547
- externalhttps://issues.redhat.com/browse/OCPBUGS-26526
- externalhttps://issues.redhat.com/browse/OCPBUGS-26527
- externalhttps://issues.redhat.com/browse/OCPBUGS-27072
- externalhttps://issues.redhat.com/browse/OCPBUGS-27157
- externalhttps://issues.redhat.com/browse/OCPBUGS-27419
- externalhttps://issues.redhat.com/browse/OCPBUGS-27773
- externalhttps://issues.redhat.com/browse/OCPBUGS-28238
- externalhttps://issues.redhat.com/browse/OCPBUGS-28379
- externalhttps://issues.redhat.com/browse/OCPBUGS-28384
- externalhttps://issues.redhat.com/browse/OCPBUGS-28789
- externalhttps://issues.redhat.com/browse/OCPBUGS-28823
- externalhttps://issues.redhat.com/browse/OCPBUGS-28871
- externalhttps://issues.redhat.com/browse/OCPBUGS-28949
- externalhttps://issues.redhat.com/browse/OCPBUGS-28950
- externalhttps://issues.redhat.com/browse/OCPBUGS-28951
- externalhttps://issues.redhat.com/browse/OCPBUGS-28952
- externalhttps://issues.redhat.com/browse/OCPBUGS-28957
- externalhttps://issues.redhat.com/browse/OCPBUGS-29030
- externalhttps://issues.redhat.com/browse/OCPBUGS-29034
- externalhttps://issues.redhat.com/browse/OCPBUGS-7262
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0735.json