RedHat: RHSA-2023-4286:01 Moderate: Red Hat OpenShift Dev Spaces Security
Summary
Red Hat OpenShift Dev Spaces provides a cloud developer workspace server
and a
browser-based IDE built for teams and organizations. Dev Spaces runs in
OpenShift and is well-suited for container-based development.
Security Fix(es):
* openshift: OCP & FIPS mode (CVE-2023-3089)
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2022-48281 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-22006 https://access.redhat.com/security/cve/CVE-2023-22036 https://access.redhat.com/security/cve/CVE-2023-22041 https://access.redhat.com/security/cve/CVE-2023-22045 https://access.redhat.com/security/cve/CVE-2023-22049 https://access.redhat.com/security/cve/CVE-2023-25193 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/cve/CVE-2023-28466 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001
Package List
Topic
Red Hat OpenShift Dev Spaces provides a cloud developer workspace serverand abrowser-based IDE built for teams and organizations. Dev Spaces runs inOpenShift and is well-suited for container-based development.The 3.7.1 release is based on Eclipse Che 7.67.Dev Spaces releases support the latest two OpenShift 4 EUS releases. Usersareexpected to update to newer OpenShift releases in order to continue to getDevSpaces updates.https://access.redhat.com/support/policy/updates/openshift#crwRed Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
2212085 - CVE-2023-3089 openshift: OCP & FIPS mode