First published: Wed Apr 27 2022(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container<br>Platform 3.11.685. See the following advisory for the container images for this release:<br><a href="https://access.redhat.com/errata/RHBA-2022:1421" target="_blank">https://access.redhat.com/errata/RHBA-2022:1421</a> Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:<br><a href="https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html" target="_blank">https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html</a> <br>Security Fix(es):<br><li> workflow-cps: OS command execution through crafted SCM contents (CVE-2022-25173)</li> <li> workflow-cps-global-lib: OS command execution through crafted SCM contents (CVE-2022-25174)</li> <li> workflow-multibranch: OS command execution through crafted SCM contents (CVE-2022-25175)</li> <li> workflow-cps-global-lib: Sandbox bypass vulnerability (CVE-2022-25181)</li> <li> workflow-cps-global-lib: Sandbox bypass vulnerability (CVE-2022-25182)</li> <li> workflow-cps-global-lib: Sandbox bypass vulnerability (CVE-2022-25183)</li> <li> xstream: Injecting highly recursive collections or maps can cause a DoS (CVE-2021-43859)</li> <li> workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names (CVE-2022-25176)</li> <li> workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names (CVE-2022-25177)</li> <li> workflow-cps-global-lib: Pipeline-related plugins follow symbolic links or do not limit path names (CVE-2022-25178)</li> <li> workflow-multibranch: Pipeline-related plugins follow symbolic links or do not limit path names (CVE-2022-25179)</li> <li> workflow-cps: Password parameters are included from the original build in replayed builds (CVE-2022-25180)</li> <li> pipeline-build-step: Password parameter default values exposed (CVE-2022-25184)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/atomic-enterprise-service-catalog | <3.11.685-1.g2e6be86.el7 | 3.11.685-1.g2e6be86.el7 |
redhat/atomic-openshift | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.685-1.g99b2acf.el7 | 3.11.685-1.g99b2acf.el7 |
redhat/atomic-openshift-descheduler | <3.11.685-1.gd435537.el7 | 3.11.685-1.gd435537.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.685-1.g3571208.el7 | 3.11.685-1.g3571208.el7 |
redhat/atomic-openshift-metrics-server | <3.11.685-1.gf8bf728.el7 | 3.11.685-1.gf8bf728.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.685-1.gc8f26da.el7 | 3.11.685-1.gc8f26da.el7 |
redhat/atomic-openshift-service-idler | <3.11.685-1.g39cfc66.el7 | 3.11.685-1.g39cfc66.el7 |
redhat/atomic-openshift-web-console | <3.11.685-1.gd742e61.el7 | 3.11.685-1.gd742e61.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.685-1.gedebe84.el7 | 3.11.685-1.gedebe84.el7 |
redhat/golang-github-prometheus-alertmanager | <3.11.685-1.g13de638.el7 | 3.11.685-1.g13de638.el7 |
redhat/golang-github-prometheus-prometheus | <3.11.685-1.g99aae51.el7 | 3.11.685-1.g99aae51.el7 |
redhat/jenkins | <2-plugins-3.11.1650371376-1.el7 | 2-plugins-3.11.1650371376-1.el7 |
redhat/jenkins | <2.319.3.1650348949-1.el7 | 2.319.3.1650348949-1.el7 |
redhat/openshift-ansible | <3.11.685-1.git.0.a9090ac.el7 | 3.11.685-1.git.0.a9090ac.el7 |
redhat/openshift-enterprise-autoheal | <3.11.685-1.gf2f435d.el7 | 3.11.685-1.gf2f435d.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.685-1.g22be164.el7 | 3.11.685-1.g22be164.el7 |
redhat/openshift-kuryr | <3.11.685-1.g0c4bf66.el7 | 3.11.685-1.g0c4bf66.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.685-1.g2e6be86.el7 | 3.11.685-1.g2e6be86.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.685-1.g2e6be86.el7 | 3.11.685-1.g2e6be86.el7 |
redhat/atomic-openshift | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-clients | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-clients-redistributable | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.685-1.g99b2acf.el7 | 3.11.685-1.g99b2acf.el7 |
redhat/atomic-openshift-descheduler | <3.11.685-1.gd435537.el7 | 3.11.685-1.gd435537.el7 |
redhat/atomic-openshift-docker-excluder | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-dockerregistry | <3.11.685-1.g3571208.el7 | 3.11.685-1.g3571208.el7 |
redhat/atomic-openshift-excluder | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-hyperkube | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-hypershift | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-master | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-metrics-server | <3.11.685-1.gf8bf728.el7 | 3.11.685-1.gf8bf728.el7 |
redhat/atomic-openshift-node | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.685-1.gc8f26da.el7 | 3.11.685-1.gc8f26da.el7 |
redhat/atomic-openshift-pod | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-sdn-ovs | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-service-idler | <3.11.685-1.g39cfc66.el7 | 3.11.685-1.g39cfc66.el7 |
redhat/atomic-openshift-template-service-broker | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-tests | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-web-console | <3.11.685-1.gd742e61.el7 | 3.11.685-1.gd742e61.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.685-1.gedebe84.el7 | 3.11.685-1.gedebe84.el7 |
redhat/jenkins | <2-plugins-3.11.1650371376-1.el7 | 2-plugins-3.11.1650371376-1.el7 |
redhat/jenkins | <2.319.3.1650348949-1.el7 | 2.319.3.1650348949-1.el7 |
redhat/openshift-ansible | <3.11.685-1.git.0.a9090ac.el7 | 3.11.685-1.git.0.a9090ac.el7 |
redhat/openshift-ansible-docs | <3.11.685-1.git.0.a9090ac.el7 | 3.11.685-1.git.0.a9090ac.el7 |
redhat/openshift-ansible-playbooks | <3.11.685-1.git.0.a9090ac.el7 | 3.11.685-1.git.0.a9090ac.el7 |
redhat/openshift-ansible-roles | <3.11.685-1.git.0.a9090ac.el7 | 3.11.685-1.git.0.a9090ac.el7 |
redhat/openshift-enterprise-autoheal | <3.11.685-1.gf2f435d.el7 | 3.11.685-1.gf2f435d.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.685-1.g22be164.el7 | 3.11.685-1.g22be164.el7 |
redhat/openshift-kuryr-cni | <3.11.685-1.g0c4bf66.el7 | 3.11.685-1.g0c4bf66.el7 |
redhat/openshift-kuryr-common | <3.11.685-1.g0c4bf66.el7 | 3.11.685-1.g0c4bf66.el7 |
redhat/openshift-kuryr-controller | <3.11.685-1.g0c4bf66.el7 | 3.11.685-1.g0c4bf66.el7 |
redhat/prometheus | <3.11.685-1.g99aae51.el7 | 3.11.685-1.g99aae51.el7 |
redhat/prometheus-alertmanager | <3.11.685-1.g13de638.el7 | 3.11.685-1.g13de638.el7 |
redhat/prometheus-node-exporter | <3.11.685-1.g609cd20.el7 | 3.11.685-1.g609cd20.el7 |
redhat/python2-kuryr-kubernetes | <3.11.685-1.g0c4bf66.el7 | 3.11.685-1.g0c4bf66.el7 |
redhat/atomic-enterprise-service-catalog | <3.11.685-1.g2e6be86.el7 | 3.11.685-1.g2e6be86.el7 |
redhat/atomic-enterprise-service-catalog-svcat | <3.11.685-1.g2e6be86.el7 | 3.11.685-1.g2e6be86.el7 |
redhat/atomic-openshift | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-clients | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-cluster-autoscaler | <3.11.685-1.g99b2acf.el7 | 3.11.685-1.g99b2acf.el7 |
redhat/atomic-openshift-descheduler | <3.11.685-1.gd435537.el7 | 3.11.685-1.gd435537.el7 |
redhat/atomic-openshift-hyperkube | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-hypershift | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-master | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-metrics-server | <3.11.685-1.gf8bf728.el7 | 3.11.685-1.gf8bf728.el7 |
redhat/atomic-openshift-node | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-node-problem-detector | <3.11.685-1.gc8f26da.el7 | 3.11.685-1.gc8f26da.el7 |
redhat/atomic-openshift-pod | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-sdn-ovs | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-service-idler | <3.11.685-1.g39cfc66.el7 | 3.11.685-1.g39cfc66.el7 |
redhat/atomic-openshift-template-service-broker | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-tests | <3.11.685-1.git.0.7faaeaa.el7 | 3.11.685-1.git.0.7faaeaa.el7 |
redhat/atomic-openshift-web-console | <3.11.685-1.gd742e61.el7 | 3.11.685-1.gd742e61.el7 |
redhat/golang-github-openshift-oauth-proxy | <3.11.685-1.gedebe84.el7 | 3.11.685-1.gedebe84.el7 |
redhat/openshift-ansible-test | <3.11.685-1.git.0.a9090ac.el7 | 3.11.685-1.git.0.a9090ac.el7 |
redhat/openshift-enterprise-autoheal | <3.11.685-1.gf2f435d.el7 | 3.11.685-1.gf2f435d.el7 |
redhat/openshift-enterprise-cluster-capacity | <3.11.685-1.g22be164.el7 | 3.11.685-1.g22be164.el7 |
redhat/prometheus | <3.11.685-1.g99aae51.el7 | 3.11.685-1.g99aae51.el7 |
redhat/prometheus-alertmanager | <3.11.685-1.g13de638.el7 | 3.11.685-1.g13de638.el7 |
redhat/prometheus-node-exporter | <3.11.685-1.g609cd20.el7 | 3.11.685-1.g609cd20.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.