RHSA-2023:0237: Important: OpenShift Container Platform 4.8.57 security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements (CVE-2022-41912)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0237?
The severity of RHSA-2023:0237 is categorized as a critical vulnerability due to authentication bypass in SAML responses.
How do I fix RHSA-2023:0237?
To fix RHSA-2023:0237, upgrade the affected Red Hat OpenShift Container Platform to the latest version provided by Red Hat.
What products are affected by RHSA-2023:0237?
RHSA-2023:0237 affects the Red Hat OpenShift Container Platform and its deployments.
What type of vulnerability is RHSA-2023:0237?
RHSA-2023:0237 is an authentication bypass vulnerability when processing SAML responses in the crewjam/saml package.
Is there a workaround for RHSA-2023:0237?
No formal workaround is provided for RHSA-2023:0237; upgrading to the patched version is the only recommended action.