RedHat: RHSA-2023-3342:01 Moderate: OpenShift Container Platform 4.13.4 CNF
Summary
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the extra low-latency container images for Red Hat
OpenShift Container Platform 4.13. See the following advisory for the
container images for this release:
https://access.redhat.com/errata/RHSA-2023:3614
All OpenShift Container Platform users are advised to upgrade to these
updated packages and images.
Security Fix(es):
* vault: Hashicorp Vault AWS IAM Integration Authentication Bypass
(CVE-2020-16250)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2020-16250 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification/#moderate
Package List
Topic
An update for ztp-site-generate-container, topology-aware-lifecycle-managerand bare-metal-event-relay is now available for Red Hat OpenShift ContainerPlatform 4.13.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
2167337 - CVE-2020-16250 vault: Hashicorp Vault AWS IAM Integration Authentication Bypass
5. JIRA issues fixed (https://issues.redhat.com/):
OCPBUGS-13161 - SiteConfig disk partition definition fails when applied to multiple nodes in a cluster
OCPBUGS-13700 - Misleading backup conditions in CGU when all clusters are already compliant
OCPBUGS-7422 - Occasionally an entire CGU will fail to upgrade with BackupTimeout while upgrading many clusters at scale