QID 770014

Date Published: 2021-06-21

QID 770014: Red Hat OpenShift Container Platform 4.3.5 Security Update (RHSA-2020:0680)

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. The podman tool manages Pods, container images, and containers. It is part of the libpod library, which is for applications that use container Pods. Container Pods is a concept in Kubernetes.

Security Fix(es):
podman: incorrectly allowed existing files in volumes to be overwritten by a container when it was created (CVE-2020-1726)

Affected Products:
Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64

A successful exploitation could allow an attacker to execute an arbitrary code on the system.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to upgrade to the latest patch level. Please refer to Red Hat security advisory RHSA-2020:0680 to address this issue.

    Vendor References

    CVEs related to QID 770014

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2020:0680 Red Hat Enterprise Linux CoreOS URL Logo access.redhat.com/errata/RHSA-2020:0680?language=en