First published: Wed Apr 26 2023(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.10.58. See the following advisory for the container images for this release:<br><a href="https://access.redhat.com/errata/RHBA-2023:1867" target="_blank">https://access.redhat.com/errata/RHBA-2023:1867</a> Security Fix(es):<br><li> apache-commons-text: variable interpolation RCE (CVE-2022-42889)</li> <li> jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin (CVE-2023-25761)</li> <li> jenkins-2-plugins/pipeline-build-step: Stored XSS vulnerability in Pipeline: Build Step Plugin (CVE-2023-25762)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cri-o | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/jenkins | <2-plugins-4.10.1681719745-1.el8 | 2-plugins-4.10.1681719745-1.el8 |
redhat/jenkins | <2.387.1.1681718871-1.el8 | 2.387.1.1681718871-1.el8 |
redhat/cri-o | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o-debuginfo | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o-debugsource | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/jenkins | <2-plugins-4.10.1681719745-1.el8 | 2-plugins-4.10.1681719745-1.el8 |
redhat/jenkins | <2.387.1.1681718871-1.el8 | 2.387.1.1681718871-1.el8 |
redhat/cri-o | <1.23.5-10.rhaos4.10.gitcc8441d.el7 | 1.23.5-10.rhaos4.10.gitcc8441d.el7 |
redhat/cri-o | <1.23.5-10.rhaos4.10.gitcc8441d.el7 | 1.23.5-10.rhaos4.10.gitcc8441d.el7 |
redhat/cri-o-debuginfo | <1.23.5-10.rhaos4.10.gitcc8441d.el7 | 1.23.5-10.rhaos4.10.gitcc8441d.el7 |
redhat/cri-o | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o-debuginfo | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o-debugsource | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o-debuginfo | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o-debugsource | <1.23.5-10.rhaos4.10.gitcc8441d.el8 | 1.23.5-10.rhaos4.10.gitcc8441d.el8 |
redhat/cri-o | <1.23.5-10.rhaos4.10.gitcc8441d.el8.aa | 1.23.5-10.rhaos4.10.gitcc8441d.el8.aa |
redhat/cri-o-debuginfo | <1.23.5-10.rhaos4.10.gitcc8441d.el8.aa | 1.23.5-10.rhaos4.10.gitcc8441d.el8.aa |
redhat/cri-o-debugsource | <1.23.5-10.rhaos4.10.gitcc8441d.el8.aa | 1.23.5-10.rhaos4.10.gitcc8441d.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.