RHSA-2019:2859: Moderate: OpenShift Container Platform 4.1.18 security update
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> A flaw was found in the way the DES/3DES cipher was used as part of the TLS/SSL protocol. A man-in-the-middle attacker could use this flaw to recover some plaintext data by capturing large amounts of encrypted traffic between TLS/SSL server and client if the communication used a DES/3DES based ciphersuite. (CVE-2016-2183)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2859?
The severity of RHSA-2019:2859 is classified as moderate.
How do I fix RHSA-2019:2859?
To fix RHSA-2019:2859, you should update your Red Hat OpenShift Container Platform to the latest available version.
What vulnerability does RHSA-2019:2859 address?
RHSA-2019:2859 addresses a flaw in the use of the DES/3DES cipher within the TLS/SSL protocol.
Which versions of Red Hat OpenShift Container Platform are affected by RHSA-2019:2859?
RHSA-2019:2859 affects multiple versions of Red Hat OpenShift Container Platform that implement the vulnerable DES/3DES cipher.
Is there a workaround for RHSA-2019:2859 while patches are being applied?
While a specific workaround for RHSA-2019:2859 is not provided, it is advised to disable the use of DES/3DES ciphers if possible.