First published: Thu Oct 24 2019(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>This advisory contains RPM packages for Red Hat OpenShift Container<br>Platform 3.9, which have been rebuilt with an updated version of golang.<br>Security Fix(es):<br><li> HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</li> <li> HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</li> <li> kubernetes: API server allows access to cluster-scoped custom resources as if resources were namespaced (CVE-2019-11247)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ansible-service-broker | <1.1.20-2.el7 | 1.1.20-2.el7 |
redhat/atomic-openshift | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-descheduler | <3.9.13-2.git.267.bb59a3f.el7 | 3.9.13-2.git.267.bb59a3f.el7 |
redhat/atomic-openshift-node-problem-detector | <3.9.13-2.git.167.5d6b0d4.el7 | 3.9.13-2.git.167.5d6b0d4.el7 |
redhat/atomic-openshift-web-console | <3.9.101-1.git.1.601c6d2.el7 | 3.9.101-1.git.1.601c6d2.el7 |
redhat/cockpit | <195-2.rhaos.el7 | 195-2.rhaos.el7 |
redhat/containernetworking-plugins | <0.5.2-6.el7 | 0.5.2-6.el7 |
redhat/cri-o | <1.9.16-3.git858756d.el7 | 1.9.16-3.git858756d.el7 |
redhat/cri-tools | <1.0.0-6.rhaos3.9.git8e6013a.el7 | 1.0.0-6.rhaos3.9.git8e6013a.el7 |
redhat/golang-github-openshift-oauth-proxy | <2.1-3.git885c9f40.el7 | 2.1-3.git885c9f40.el7 |
redhat/golang-github-openshift-prometheus-alert-buffer | <0-3.gitceca8c1.el7 | 0-3.gitceca8c1.el7 |
redhat/golang-github-prometheus-alertmanager | <0.14.0-2.git30af4d0.el7 | 0.14.0-2.git30af4d0.el7 |
redhat/golang-github-prometheus-prometheus | <2.2.1-2.gitbc6058c.el7 | 2.2.1-2.gitbc6058c.el7 |
redhat/golang-github-prometheus-promu | <0-5.git85ceabc.el7 | 0-5.git85ceabc.el7 |
redhat/hawkular-openshift-agent | <1.2.2-3.el7 | 1.2.2-3.el7 |
redhat/heapster | <1.3.0-4.el7 | 1.3.0-4.el7 |
redhat/image-inspector | <2.1.3-2.el7 | 2.1.3-2.el7 |
redhat/openshift-enterprise-image-registry | <3.8.0-2.git.216.b6b90bb.el7 | 3.8.0-2.git.216.b6b90bb.el7 |
redhat/openshift-eventrouter | <0.1-3.git5bd9251.el7 | 0.1-3.git5bd9251.el7 |
redhat/openshift-external-storage | <0.0.1-9.git78d6339.el7 | 0.0.1-9.git78d6339.el7 |
redhat/openvswitch-ovn-kubernetes | <0.1.0-3.el7 | 0.1.0-3.el7 |
redhat/ansible-service-broker | <1.1.20-2.el7 | 1.1.20-2.el7 |
redhat/ansible-service-broker-container-scripts | <1.1.20-2.el7 | 1.1.20-2.el7 |
redhat/ansible-service-broker-selinux | <1.1.20-2.el7 | 1.1.20-2.el7 |
redhat/atomic-openshift | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-clients | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-clients-redistributable | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-cluster-capacity | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-descheduler | <3.9.13-2.git.267.bb59a3f.el7 | 3.9.13-2.git.267.bb59a3f.el7 |
redhat/atomic-openshift-docker-excluder | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-dockerregistry | <3.9.101-1.git.1.13625cf.el7 | 3.9.101-1.git.1.13625cf.el7 |
redhat/atomic-openshift-excluder | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-federation-services | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-master | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-node | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-node-problem-detector | <3.9.13-2.git.167.5d6b0d4.el7 | 3.9.13-2.git.167.5d6b0d4.el7 |
redhat/atomic-openshift-pod | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-sdn-ovs | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-service-catalog | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-template-service-broker | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-tests | <3.9.101-1.git.0.150f595.el7 | 3.9.101-1.git.0.150f595.el7 |
redhat/atomic-openshift-web-console | <3.9.101-1.git.1.601c6d2.el7 | 3.9.101-1.git.1.601c6d2.el7 |
redhat/cockpit-debuginfo | <195-2.rhaos.el7 | 195-2.rhaos.el7 |
redhat/cockpit-kubernetes | <195-2.rhaos.el7 | 195-2.rhaos.el7 |
redhat/containernetworking-plugins | <0.5.2-6.el7 | 0.5.2-6.el7 |
redhat/containernetworking-plugins-debuginfo | <0.5.2-6.el7 | 0.5.2-6.el7 |
redhat/cri-o | <1.9.16-3.git858756d.el7 | 1.9.16-3.git858756d.el7 |
redhat/cri-o-debuginfo | <1.9.16-3.git858756d.el7 | 1.9.16-3.git858756d.el7 |
redhat/cri-tools | <1.0.0-6.rhaos3.9.git8e6013a.el7 | 1.0.0-6.rhaos3.9.git8e6013a.el7 |
redhat/cri-tools-debuginfo | <1.0.0-6.rhaos3.9.git8e6013a.el7 | 1.0.0-6.rhaos3.9.git8e6013a.el7 |
redhat/golang-github-openshift-oauth-proxy | <2.1-3.git885c9f40.el7 | 2.1-3.git885c9f40.el7 |
redhat/golang-github-openshift-prometheus-alert-buffer | <0-3.gitceca8c1.el7 | 0-3.gitceca8c1.el7 |
redhat/golang-github-prometheus-promu | <0-5.git85ceabc.el7 | 0-5.git85ceabc.el7 |
redhat/hawkular-openshift-agent | <1.2.2-3.el7 | 1.2.2-3.el7 |
redhat/heapster | <1.3.0-4.el7 | 1.3.0-4.el7 |
redhat/image-inspector | <2.1.3-2.el7 | 2.1.3-2.el7 |
redhat/openshift-enterprise-image-registry | <3.8.0-2.git.216.b6b90bb.el7 | 3.8.0-2.git.216.b6b90bb.el7 |
redhat/openshift-eventrouter | <0.1-3.git5bd9251.el7 | 0.1-3.git5bd9251.el7 |
redhat/openshift-eventrouter-debuginfo | <0.1-3.git5bd9251.el7 | 0.1-3.git5bd9251.el7 |
redhat/openshift-external-storage-debuginfo | <0.0.1-9.git78d6339.el7 | 0.0.1-9.git78d6339.el7 |
redhat/openshift-external-storage-efs-provisioner | <0.0.1-9.git78d6339.el7 | 0.0.1-9.git78d6339.el7 |
redhat/openshift-external-storage-local-provisioner | <0.0.1-9.git78d6339.el7 | 0.0.1-9.git78d6339.el7 |
redhat/openshift-external-storage-snapshot-controller | <0.0.1-9.git78d6339.el7 | 0.0.1-9.git78d6339.el7 |
redhat/openshift-external-storage-snapshot-provisioner | <0.0.1-9.git78d6339.el7 | 0.0.1-9.git78d6339.el7 |
redhat/openvswitch-ovn-kubernetes | <0.1.0-3.el7 | 0.1.0-3.el7 |
redhat/prometheus | <2.2.1-2.gitbc6058c.el7 | 2.2.1-2.gitbc6058c.el7 |
redhat/prometheus-alertmanager | <0.14.0-2.git30af4d0.el7 | 0.14.0-2.git30af4d0.el7 |
redhat/prometheus-node-exporter | <3.9.101-1.git.1.8295224.el7 | 3.9.101-1.git.1.8295224.el7 |
redhat/prometheus-promu | <0-5.git85ceabc.el7 | 0-5.git85ceabc.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:2769 is classified as moderate.
To fix RHSA-2019:2769, you should update the affected RPM packages to the recommended versions.
RHSA-2019:2769 affects multiple packages including ansible-service-broker, atomic-openshift, and cockpit among others.
There are no specific workarounds provided for RHSA-2019:2769; applying the updates is recommended.
More information about RHSA-2019:2769 can typically be found in the Red Hat advisory and bug reports related to this vulnerability.