RHSA-2019:3007: Moderate: OpenShift Container Platform 4.1.20 openshift-enterprise-builder-container security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.This advisory contains the openshift-enterprise-builder container image for Red Hat OpenShift Container Platform 4.1.20. Security Fix(es): atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository (CVE-2019-10150) containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure (CVE-2019-10214) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3007?
The severity of RHSA-2019:3007 is classified as moderate.
What vulnerabilities are addressed in RHSA-2019:3007?
RHSA-2019:3007 addresses multiple security vulnerabilities in the openshift-enterprise-builder container image of Red Hat OpenShift Container Platform.
How do I fix RHSA-2019:3007?
To fix RHSA-2019:3007, update the openshift-enterprise-builder container image to the latest recommended version.
Who is affected by RHSA-2019:3007?
Users of Red Hat OpenShift Container Platform 4 who utilize the openshift-enterprise-builder container image are affected by RHSA-2019:3007.
Where can I find more information about RHSA-2019:3007?
For more details on RHSA-2019:3007, refer to the official Red Hat advisory documentation.