RHSA-2020:1401: Important: OpenShift Container Platform 4.2.28 security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): buildah: crafted input tar file may lead to local file overwriting during image build process (CVE-2020-10696) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1401?
The vulnerability RHSA-2020:1401 is classified as important.
How do I fix RHSA-2020:1401?
To fix RHSA-2020:1401, update to the recommended version 1.4.2-6.rhaos4.2.el8 of the affected packages.
Which versions of Podman are affected by RHSA-2020:1401?
Podman versions up to, but not including, 1.4.2-6.rhaos4.2.el8 are affected by RHSA-2020:1401.
What issue does RHSA-2020:1401 address?
RHSA-2020:1401 addresses a vulnerability that allows crafted input tar files to overwrite local files during image builds.
Is RHSA-2020:1401 relevant for all deployments of OpenShift?
Yes, RHSA-2020:1401 is relevant for all deployments of Red Hat OpenShift Container Platform that use affected versions of Podman.