RHSA-2021:3193: Moderate: OpenShift Container Platform 3.11.z security and bug fix update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): kubernetes: Docker config secrets leaked when file is malformed and loglevel >= 4 (CVE-2020-8564) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): [3.11] Wrong message error displayed when creating a route with path based (BZ#1884421) [3.11] passthrough route created using path (BZ#1884422) Hawkular cassandra pod readiness probe failed when run on the CRIO node. (BZ#1958718) Pods are getting stuck in ContainerCreating/ContainerCreateError/Terminating status (BZ#1965900) [3.11.z] Egress IP iptables rules not added due to iptables: Resource temporarily unavailable (BZ#1979216) Slowness in services propagation after upgrading to v3.11.465 (BZ#1981736) [3.11] NodePort is not working when configuring an egress IP address (BZ#1986413)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/atomic-enterprise-service-catalogto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.2e6be86.el7 - Upgrade
Upgrade
redhat/atomic-openshiftto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-cluster-autoscalerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.99b2acf.el7 - Upgrade
Upgrade
redhat/atomic-openshift-deschedulerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.d435537.el7 - Upgrade
Upgrade
redhat/atomic-openshift-dockerregistryto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.3571208.el7 - Upgrade
Upgrade
redhat/atomic-openshift-metrics-serverto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.f8bf728.el7 - Upgrade
Upgrade
redhat/atomic-openshift-node-problem-detectorto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.c8f26da.el7 - Upgrade
Upgrade
redhat/atomic-openshift-service-idlerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.39cfc66.el7 - Upgrade
Upgrade
redhat/atomic-openshift-web-consoleto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.fc3b323.el7 - Upgrade
Upgrade
redhat/cri-oto a version that resolves this vulnerability.Fixed in 1.11.16-0.16.rhaos3.11.git54f9e69.el7 - Upgrade
Upgrade
redhat/golang-github-openshift-oauth-proxyto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.edebe84.el7 - Upgrade
Upgrade
redhat/golang-github-prometheus-alertmanagerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.13de638.el7 - Upgrade
Upgrade
redhat/golang-github-prometheus-prometheusto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.99aae51.el7 - Upgrade
Upgrade
redhat/openshift-ansibleto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.5ea39b1.el7 - Upgrade
Upgrade
redhat/openshift-enterprise-autohealto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.f2f435d.el7 - Upgrade
Upgrade
redhat/openshift-enterprise-cluster-capacityto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.22be164.el7 - Upgrade
Upgrade
redhat/openshift-kuryrto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.c33a657.el7 - Upgrade
Upgrade
redhat/atomic-enterprise-service-catalog-svcatto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.2e6be86.el7 - Upgrade
Upgrade
redhat/atomic-openshift-clientsto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-clients-redistributableto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-docker-excluderto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-excluderto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-hyperkubeto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-hypershiftto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-masterto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-nodeto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-podto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-sdn-ovsto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-template-service-brokerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/atomic-openshift-teststo a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.f8c4746.el7 - Upgrade
Upgrade
redhat/cri-o-debuginfoto a version that resolves this vulnerability.Fixed in 1.11.16-0.16.rhaos3.11.git54f9e69.el7 - Upgrade
Upgrade
redhat/openshift-ansible-docsto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.5ea39b1.el7 - Upgrade
Upgrade
redhat/openshift-ansible-playbooksto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.5ea39b1.el7 - Upgrade
Upgrade
redhat/openshift-ansible-rolesto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.5ea39b1.el7 - Upgrade
Upgrade
redhat/openshift-kuryr-cnito a version that resolves this vulnerability.Fixed in 3.11.501-1.git.c33a657.el7 - Upgrade
Upgrade
redhat/openshift-kuryr-commonto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.c33a657.el7 - Upgrade
Upgrade
redhat/openshift-kuryr-controllerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.c33a657.el7 - Upgrade
Upgrade
redhat/prometheusto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.99aae51.el7 - Upgrade
Upgrade
redhat/prometheus-alertmanagerto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.13de638.el7 - Upgrade
Upgrade
redhat/prometheus-node-exporterto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.609cd20.el7 - Upgrade
Upgrade
redhat/python2-kuryr-kubernetesto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.c33a657.el7 - Upgrade
Upgrade
redhat/openshift-ansible-testto a version that resolves this vulnerability.Fixed in 3.11.501-1.git.0.5ea39b1.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3193?
The severity of RHSA-2021:3193 is classified as Moderate due to the risk of leaking Docker config secrets.
How do I fix RHSA-2021:3193?
To fix RHSA-2021:3193, update to the specified patched package versions as per the advisory guidelines.
What products are affected by RHSA-2021:3193?
RHSA-2021:3193 affects multiple products including Red Hat OpenShift Container Platform and various associated packages.
What is the nature of the vulnerability addressed in RHSA-2021:3193?
RHSA-2021:3193 addresses vulnerabilities where improperly formatted files can lead to the exposure of sensitive information.
Is there a known exploit for RHSA-2021:3193?
As of the advisory, there are no known active exploits specifically targeting the vulnerability fixed in RHSA-2021:3193.