RHSA-2016:0070: Important: Red Hat OpenShift Enterprise 3.1.1 bug fix and enhancement update
OpenShift Enterprise by Red Hat is the company's cloud computing <br>Platform-as-a-Service (PaaS) solution designed for on-premise or <br>private cloud deployments.<br>The following security issues are addressed with this release:<br>An authorization flaw was discovered in Kubernetes; the API server <br>did not properly check user permissions when handling certain <br>requests. An authenticated remote attacker could use this flaw to <br>gain additional access to resources such as RAM and disk space. <br>(CVE-2016-1905)<br>An authorization flaw was discovered in Kubernetes; the API server <br>did not properly check user permissions when handling certain build-<br>configuration strategies. A remote attacker could create build <br>configurations with strategies that violate policy. Although the <br>attacker could not launch the build themselves (launch fails when <br>the policy is violated), if the build configuration files were later <br>launched by other privileged services (such as automated triggers), <br>user privileges could be bypassed allowing attacker escalation. <br>(CVE-2016-1906)<br>An update for Jenkins Continuous Integration Server that addresses a <br>large number of security issues including XSS, CSRF, information <br>disclosure and code execution have been addressed as well. <br>(CVE-2013-2186, CVE-2014-1869, CVE-2014-3661, CVE-2014-3662<br>CVE-2014-3663, CVE-2014-3664, CVE-2014-3666, CVE-2014-3667<br>CVE-2014-3680, CVE-2014-3681, CVE-2015-1806, CVE-2015-1807<br>CVE-2015-1808, CVE-2015-1810, CVE-2015-1812, CVE-2015-1813<br>CVE-2015-1814, CVE-2015-5317, CVE-2015-5318, CVE-2015-5319<br>CVE-2015-5320, CVE-2015-5321, CVE-2015-5322, CVE-2015-5323<br>CVE-2015-5324, CVE-2015-5325, CVE-2015-5326 ,CVE-2015-7537<br>CVE-2015-7538, CVE-2015-7539, CVE-2015-8103)<br>Space precludes documenting all of the bug fixes and enhancements in <br>this advisory. See the OpenShift Enterprise 3.1 Release Notes, which <br>will be updated shortly for release 3.1.1, for details about these <br>changes:<br><a href="https://docs.openshift.com/enterprise/3.1/releasenotes/ose31releasenotes.html" target="blank">https://docs.openshift.com/enterprise/3.1/releasenotes/ose31releasenotes.html</a> All OpenShift Enterprise 3 users are advised to upgrade to these <br>updated packages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2016:0070?
The severity of RHSA-2016:0070 is classified as moderate.
What are the affected packages in RHSA-2016:0070?
RHSA-2016:0070 affects multiple packages including atomic-openshift, heapster, jenkins, and several nodejs packages.
How do I fix RHSA-2016:0070?
To fix RHSA-2016:0070, upgrade the affected packages to the recommended versions as specified in the advisory.
Are there workarounds for RHSA-2016:0070?
There are no specific workarounds mentioned for RHSA-2016:0070; upgrading is the advised action.
What causes the vulnerability in RHSA-2016:0070?
RHSA-2016:0070 addresses an authorization flaw discovered in Kubernetes that could potentially lead to unauthorized access.