RHSA-2024:0641: Critical: OpenShift Container Platform 4.14.11 security and extras update
Critical: OpenShift Container Platform 4.14.11 security and extras update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.11. See the following advisory for the container images for this release:<br><a href="https://access.redhat.com/errata/RHSA-2024:0642" target="blank">https://access.redhat.com/errata/RHSA-2024:0642</a> Security Fix(es):<br><li> go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients (CVE-2023-49569)</li> <li> go-git: Maliciously crafted Git server replies can cause DoS on go-git clients (CVE-2023-49568)</li> <li> opentelemetry: DoS vulnerability in otelhttp (CVE-2023-45142)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0641?
The severity of RHSA-2024:0641 is classified as critical.
How do I fix RHSA-2024:0641?
To fix RHSA-2024:0641, you need to update to the latest RPM packages provided in the advisory.
Which products are affected by RHSA-2024:0641?
RHSA-2024:0641 affects various versions of the Red Hat OpenShift Container Platform, including those for ARM 64, IBM Z and LinuxONE, and Power.
Is RHSA-2024:0641 related to any known vulnerabilities?
Yes, RHSA-2024:0641 addresses vulnerabilities reported in previous Bugzilla advisories.
What should I do if I am unable to apply the fix for RHSA-2024:0641 immediately?
If you cannot apply the fix for RHSA-2024:0641 immediately, ensure your systems are monitored closely for any suspicious activity.