QID 770021

Date Published: 2021-06-21

QID 770021: Red Hat OpenShift Container Platform 4.3.12 Security Update (RHSA-2020:1396)

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. The podman tool manages Pods, container images, and containers. It is part of the libpod library, which is for applications that use container Pods. Container Pods is a concept in Kubernetes.

Security Fix(es):
buildah: a crafted input tar file could overwrite local files during the image build process (CVE-2020-10696)

Affected Products:
Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64

A successful exploitation could allow an attacker to execute an arbitrary code on the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution

    Customers are advised to upgrade to the latest patch level. Please refer to Red Hat security advisory RHSA-2020:1396 to address this issue.

    Vendor References

    CVEs related to QID 770021

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2020:1396 Red Hat Enterprise Linux CoreOS URL Logo access.redhat.com/errata/RHSA-2020:1396?language=en