- Issued:
- 2022-02-25
- Updated:
- 2022-02-25
RHBA-2022:0681 - Bug Fix Advisory
Synopsis
RHEA: OSUS enhancement update
Type/Severity
Bug Fix Advisory
Topic
Updated OpenShift Update Service now available for Red Hat OpenShift Container Platform v4.9
Description
The OpenShift Update Service uses the update protocol called Cincinnati, which is designed to facilitate automatic updates.
The OpenShift Update Service has been updated to make the graph-builder's www-authenticate parsing to be case insensitive. Also includes a fix for Update Service release image digest mismatch which was caused because Artifactory was not supporting Accept q weighting
Solution
Update the OpenShift Update Service to the latest version
Affected Products
- Red Hat OpenShift Container Platform 4.8 for RHEL 8 x86_64
Fixes
- BZ - 2030532 - Update Service release image digest mismatch, because Artifactory doesn't support Accept q weighting
- BZ - 2030533 - graph-builder's www-authenticate parsing is case sensitive, while RFC 7235 calls for case-insensitive auth-schemes
- BZ - 2055460 - OUS uses wrong imagePullPolicy for graph-data initContainer
CVEs
- CVE-2019-5827
- CVE-2019-13750
- CVE-2019-13751
- CVE-2019-17594
- CVE-2019-17595
- CVE-2019-18218
- CVE-2019-19603
- CVE-2019-20838
- CVE-2020-12762
- CVE-2020-13435
- CVE-2020-14155
- CVE-2020-16135
- CVE-2020-24370
- CVE-2021-3200
- CVE-2021-3445
- CVE-2021-3521
- CVE-2021-3580
- CVE-2021-3712
- CVE-2021-3800
- CVE-2021-20231
- CVE-2021-20232
- CVE-2021-22876
- CVE-2021-22898
- CVE-2021-22925
- CVE-2021-27645
- CVE-2021-28153
- CVE-2021-33560
- CVE-2021-33574
- CVE-2021-35942
- CVE-2021-36084
- CVE-2021-36085
- CVE-2021-36086
- CVE-2021-36087
- CVE-2021-42574
References
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.