First published: Wed Aug 16 2023(Updated: )
Release of Red Hat OpenStack Platform 17.1 (Wallaby) director Operator containers provides these changes:<br>Security Fix(es):<br><li> github.com/Masterminds/vcs: Command Injection via argument injection (CVE-2022-21235)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack Platform 13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:4582 is classified as critical due to the command injection vulnerability.
To fix RHSA-2023:4582, you should update your Red Hat OpenStack Platform to the latest version provided in the security advisory.
RHSA-2023:4582 addresses a command injection vulnerability identified as CVE-2022-21235.
RHSA-2023:4582 affects Red Hat OpenStack Platform installations that utilize the vulnerable operator containers.
There are no documented workarounds for RHSA-2023:4582, so upgrading to the patched version is recommended.