RHSA-2023:4582: Moderate: Release of containers for Red Hat OpenStack Platform 17.1 director Operator
Release of Red Hat OpenStack Platform 17.1 (Wallaby) director Operator containers provides these changes:Security Fix(es): github.com/Masterminds/vcs: Command Injection via argument injection (CVE-2022-21235) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4582?
The severity of RHSA-2023:4582 is classified as critical due to the command injection vulnerability.
How do I fix RHSA-2023:4582?
To fix RHSA-2023:4582, you should update your Red Hat OpenStack Platform to the latest version provided in the security advisory.
What specific vulnerability is addressed in RHSA-2023:4582?
RHSA-2023:4582 addresses a command injection vulnerability identified as CVE-2022-21235.
Which systems are affected by RHSA-2023:4582?
RHSA-2023:4582 affects Red Hat OpenStack Platform installations that utilize the vulnerable operator containers.
Is there a workaround for the vulnerability in RHSA-2023:4582?
There are no documented workarounds for RHSA-2023:4582, so upgrading to the patched version is recommended.