First published: Wed Apr 22 2020(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> kubernetes: Use of unbounded 'client' label in apiserver_request_total allowed for memory exhaustion (CVE-2020-8552)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openshift | <4.2.29-202004110432.git.0.f7d02c8.el8 | 4.2.29-202004110432.git.0.f7d02c8.el8 |
redhat/openshift-hyperkube | <4.2.29-202004110432.git.0.f7d02c8.el8 | 4.2.29-202004110432.git.0.f7d02c8.el8 |
redhat/openshift | <4.2.29-202004120346.git.0.d948116.el7 | 4.2.29-202004120346.git.0.d948116.el7 |
redhat/openshift-hyperkube | <4.2.29-202004120346.git.0.d948116.el7 | 4.2.29-202004120346.git.0.d948116.el7 |
redhat/openshift-hyperkube | <4.2.29-202004110432.git.0.f7d02c8.el8 | 4.2.29-202004110432.git.0.f7d02c8.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:1527 is classified as important.
To fix RHSA-2020:1527, you should upgrade to the specified remedied versions of OpenShift and OpenShift Hyperkube provided in the advisory.
RHSA-2020:1527 affects OpenShift and OpenShift Hyperkube versions prior to 4.2.29-202004110432.git.0.f7d02c8.el8 for el8 and 4.2.29-202004120346.git.0.d948116.el7 for el7.
RHSA-2020:1527 addresses a vulnerability in Kubernetes regarding the unbounded 'client' label in apiserver_request_total, which could potentially lead to memory exhaustion.
Yes, RHSA-2020:1527 is applicable to both el7 and el8 versions of OpenShift and OpenShift Hyperkube.