QID 770065

Date Published: 2021-07-14

QID 770065: Red Hat OpenShift Container Platform 4.3.40 Security Update (RHSA-2020:4265)

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

Security Fix(es):
jenkins-2-plugins/matrix-project: Stored XSS vulnerability in single axis builds tooltips (CVE-2020-2224)
jenkins-2-plugins/matrix-project: Stored XSS vulnerability in multiple axis builds tooltips (CVE-2020-2225)
jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin (CVE-2020-2226
) jenkins-credentials-binding-plugin: information disclosure in build log when build contains no build steps (CVE-2020-2181)
jenkins-credentials-binding-plugin: improper masking of secrets (CVE-2020-2182)

Affected Products:
Red Hat OpenShift Container Platform 4.3 for RHEL 8 x86_64
Red Hat OpenShift Container Platform 4.3 for RHEL 7 x86_64
Red Hat OpenShift Container Platform for Power 4.3 for RHEL 8 ppc64le
Red Hat OpenShift Container Platform for Power 4.3 for RHEL 7 ppc64le
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.3 for RHEL 8 s390x
Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.3 for RHEL 7 s390x

A successful exploitation could allow an attacker to execute an arbitrary code on the system.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to upgrade to the latest patch level. Please refer to Red Hat security advisory RHSA-2020:4265 to address this issue.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2020:4265 Red Hat Enterprise Linux CoreOS URL Logo access.redhat.com/errata/RHSA-2020:4265?language=en