QID 770064
Date Published: 2021-07-22
QID 770064: Red Hat OpenShift Container Platform 4.7.0 Packages and Security Update (RHSA-2020:5634)
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.
Security Fix(es):
gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation (CVE-2021-3121)
kubernetes: Ceph RBD adminSecrets exposed in logs when loglevel >= 4 (CVE-2020-8566)
containerd: credentials leak during image pull (CVE-2020-15157)
python-rsa: bleichenbacher timing oracle attack against RSA decryption (CVE-2020-25658)
atomic-openshift: cross-namespace owner references can trigger deletions of valid children (CVE-2019-3884)
Affected Products:
Red Hat OpenShift Container Platform 4.7 for RHEL 8 x86_64
Red Hat OpenShift Container Platform 4.7 for RHEL 7 x86_64
Red Hat OpenShift Container Platform for Power 4.7 for RHEL 8 ppc64le
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.7 for RHEL 8 s390x
A successful exploitation could allow an attacker to execute an arbitrary code on the system.
Customers are advised to upgrade to the latest patch level. Please refer to Red Hat security advisory RHSA-2020:5634 to address this issue.
- RHSA-2020:5634 -
access.redhat.com/errata/RHSA-2020:5634?language=en
CVEs related to QID 770064
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| RHSA-2020:5634 | Red Hat Enterprise Linux CoreOS |
|