QID 770035

Date Published: 2021-06-21

QID 770035: Red Hat OpenShift Container Platform 4.3.31 Security Update (RHSA-2020:3183)

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

Security Fix(es):
kubernetes: A flaw was found in Kubernetes that allows attackers on adjacent networks to reach services exposed on localhost ports, previously thought to be unreachable. This flaw allows an attacker to gain privileges or access confidential information for any services listening on localhost ports that are not protected by authentication. (CVE-2020-8558)

Affected Products:
Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64
Red Hat OpenShift Container Platform 4.3 for RHEL 7 x86_64
Red Hat OpenShift Container Platform for Power 4.3 for RHEL 8 ppc64le
Red Hat OpenShift Container Platform for Power 4.3 for RHEL 7 ppc64le
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.3 for RHEL 8 s390x
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.3 for RHEL 7 s390x

A successful exploitation could allow an attacker to execute an arbitrary code on the system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution

    Customers are advised to upgrade to the latest patch level. Please refer to Red Hat security advisory RHSA-2020:3183 to address this issue.

    Vendor References

    CVEs related to QID 770035

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2020:3183 Red Hat Enterprise Linux CoreOS URL Logo access.redhat.com/errata/RHSA-2020:3183?language=en