Red Hat Security Advisory: OpenShift Container Platform 4.16.17 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-27289 — pgx: SQL Injection via Line Comment Creation
🎯 Affected products133
- Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:0137df471d6ed463d6253f5e6d76bac79e6c9bda3f1dc4b8e1993ed045f4a072_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:28d8a2b340700091ecbc61d22ef2366ecb746c595fecb52a7806a24649a6da3f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:84918802930d141544373d298bbd1420dff3cda8596ce85b46f99a432a0d7be8_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/aws-kms-encryption-provider-rhel9@sha256:b6a3169a8d4619854e2d223f348aba5496801d4ca2959396d7916e39678c0744_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:031c6a571167c24792d27066c233aeb8097102c1cb1cb747c9557a23000fcc7e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:1b5059f0211b8b90c031204eb35b151013ae9dcd0da98e7dbd7f98316453df5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:7bbdce5721440f492dae5ce2b6aaa1861be4d2669efb47440aa19825933c179e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/driver-toolkit-rhel9@sha256:e2e2e13e4d3a4521bba65985d33495d59a7f67ecc273ad3637b11bc481bf1a6d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:0fa0a3471c5c9af5d33c873d280f9ab96394b724ae72a1bb18ac6134ecfe2238_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:0fea43e30b524388e97ae4915c84cc267b626ff759ef7f3246b6eac7513497d2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:1158ecb52a1222ebea303860f27c220df158b1dc73ed5ea874c9d8a376e50d04_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/network-tools-rhel9@sha256:234fdf2af2729408d3b287b7576dd1a29f61ad7b21b303d476b1ab3367e0c886_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:317fd3a872555720eac86f5aba19b39af7d52463c7a42a3ae0c143578fd4260b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:87722d9cfdad0788902f148ef1a1c2bbcec3bbd10e622ede4309fe41bbde8f5b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:97b6ae70454b3a2a5034cfeca40b14b44fd5ec1c49f2ea106517b83b59cfa41e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-api-server-rhel9@sha256:bbff31aac52260f50f4163a281e0fb5b104bb98d6fabdfd0e1dc727955ef6c0d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:94617e923e3e16a9fd5311f171acf2094f02f245cf261f361ed490c1126e03c6_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:9bd6c062fdac47f4d886fa7cd6c141159944cc9bfdcdfd9ddb361edde5a00948_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:9d29f4f5332eace958e8b6126084f57304365fb2cf636da491255a730b48ab52_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-csr-approver-rhel9@sha256:bd1a4dc85995da2c43415f1811e87bde35afe70a8db2ab356e34f1c186c4feb3_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:1af02a31fcc970e6e788ed9a53d4abf4611a08527a5a426f5e9f5e17e6c38e50_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:8858d88b6c7e9668eecb610261f849c0afb8d250743492e7d58aaba8f4b9f245_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:b52459d42ced02f37c15f9ec9c167c515ed4c50866baa6833a6d43154753b4ff_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-agent-installer-node-agent-rhel9@sha256:d40001b336f924152385fccbb655656df3fb27d187d1912cf23cac4103ce3c77_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-baremetal-installer-rhel9@sha256:8c58e4deedd28cff6a35d41414615d5338384fcdb9168460314d21c697dc13c5_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-baremetal-installer-rhel9@sha256:8e108c2cc282221b6894793a16bb4446795c5dc66ad10272a2121badfad50d88_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-baremetal-installer-rhel9@sha256:92cc2e8990c9971f88d66d0aadeb3c7d836614ac37ffda47878c9978f15a40cd_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-baremetal-installer-rhel9@sha256:ea7e70c6a31b2a976d30eab96914e2978676f3ab7958e15a59666e4f53fb7960_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-cli-artifacts-rhel9@sha256:169763eebc41224a82981ccc0bc42c24795ec448ee04e147c3035ecf0c301978_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +103 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:a5bfe05de4c9a5cf4a5609105c539e6f8ba92731f068f13bbac94ceb855ce1d7 (For s390x architecture) The image digest is sha256:437aaa6290b7b3b57311ec605308859d3330f09c8604e91d55ea2346b709f8c2 (For ppc64le architecture) The image digest is sha256:0465e61d75adbd1a54cc661d763b25ce805c60609a0ccc86bf5819361feab8ef (For aarch64 architecture) The image digest is sha256:955bc3576eb5902ea912d4577a614ff12a502eb5d1888e431328514fe40ecc83 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: A possible mitigation is to not use the simple protocol or do not place a minus directly before a placeholder.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2024:7944
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268465
- externalhttps://issues.redhat.com/browse/OCPBUGS-33673
- externalhttps://issues.redhat.com/browse/OCPBUGS-37615
- externalhttps://issues.redhat.com/browse/OCPBUGS-38458
- externalhttps://issues.redhat.com/browse/OCPBUGS-39017
- externalhttps://issues.redhat.com/browse/OCPBUGS-39379
- externalhttps://issues.redhat.com/browse/OCPBUGS-41256
- externalhttps://issues.redhat.com/browse/OCPBUGS-41293
- externalhttps://issues.redhat.com/browse/OCPBUGS-41334
- externalhttps://issues.redhat.com/browse/OCPBUGS-41551
- externalhttps://issues.redhat.com/browse/OCPBUGS-42342
- externalhttps://issues.redhat.com/browse/OCPBUGS-42431
- externalhttps://issues.redhat.com/browse/OCPBUGS-42720
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7944.json