Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2023:1708 - Bug Fix Advisory
Issued:
2023-04-11
Updated:
2023-04-11

RHBA-2023:1708 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

updated RHEL-8 based Middleware Containers container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-8 based Middleware Containers container images are now available

Description

The RHEL-8 based Middleware Containers container images have been updated to address the following security advisory: RHSA-2023:1405 (see References)

Users of RHEL-8 based Middleware Containers container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in Red Hat Container Catalog (see References).

Solution

The RHEL-8 based Middleware Containers container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).

Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.

Affected Products

  • Red Hat OpenShift Container Platform 4.10 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.9 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.9 for RHEL 7 x86_64
  • Red Hat OpenShift Container Platform 4.8 for RHEL 7 x86_64
  • Red Hat OpenShift Container Platform 3.11 x86_64
  • Red Hat OpenShift Container Platform for Power 4.10 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.9 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.10 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.9 for RHEL 8 s390x

Fixes

  • BZ - 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName
  • BZ - 2164487 - CVE-2022-4304 openssl: timing attack in RSA Decryption implementation
  • BZ - 2164492 - CVE-2023-0215 openssl: use-after-free following BIO_new_NDEF
  • BZ - 2164494 - CVE-2022-4450 openssl: double free after calling PEM_read_bio_ex

CVEs

  • CVE-2020-10735
  • CVE-2021-28861
  • CVE-2021-46848
  • CVE-2022-1304
  • CVE-2022-4304
  • CVE-2022-4415
  • CVE-2022-4450
  • CVE-2022-22624
  • CVE-2022-22628
  • CVE-2022-22629
  • CVE-2022-22662
  • CVE-2022-26700
  • CVE-2022-26709
  • CVE-2022-26710
  • CVE-2022-26716
  • CVE-2022-26717
  • CVE-2022-26719
  • CVE-2022-30293
  • CVE-2022-35737
  • CVE-2022-40303
  • CVE-2022-40304
  • CVE-2022-40897
  • CVE-2022-42010
  • CVE-2022-42011
  • CVE-2022-42012
  • CVE-2022-43680
  • CVE-2022-45061
  • CVE-2023-0215
  • CVE-2023-0286
  • CVE-2023-23916

References

  • https://access.redhat.com/errata/RHSA-2023:1405
  • https://access.redhat.com/containers

ppc64le

fuse7/fuse-console-rhel8@sha256:b100de7fc3c572c66802355827d1cc51cf141bdb6c425014009c022c57ccaca0
fuse7/fuse-console-rhel8-operator@sha256:d9c54d92335cdc8babb6f58b4122535c51ec2bedd94e2107cdafc4993730447b
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:10bc5ec546ebadcc86667927662504e692414f0540cc379f9476320eb056df7b

s390x

fuse7/fuse-console-rhel8@sha256:1372ba7f267a1dda26832a5625b54282d8f7d58b20d1a573aaea187a5c6291c9
fuse7/fuse-console-rhel8-operator@sha256:85d21cbed477cdb35a32ad192dd249068c798711f3412eecd772304d39488869
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:c456dc0ee2afa597f2d0f272d9e424b0011c1db3ed0cf2f8e350f4c174b05c28

x86_64

fuse7/fuse-apicurito-generator-rhel8@sha256:fbeab41bb0d1b1c84230b7e3dc574b8719981e8adcf86f4df832601bebe7db26
fuse7/fuse-apicurito-rhel8@sha256:62c8c8b94c85a279d040338528c734eb6d05cb3f21f6c2068db8a78126c45122
fuse7/fuse-apicurito-rhel8-operator@sha256:94abb738d0072eafb41f4bc3a20610f0466bf00fcec1919ae146415b3e5f11b0
fuse7/fuse-console-rhel8@sha256:c9a0247bf65469729d34e9342e40e23c93704032fb405aafacedb0ac2a0a6ed6
fuse7/fuse-console-rhel8-operator@sha256:93925c158ff3627f24978e3f25e2b8a7f826fdbaa02581c33a2c3c026577776e
fuse7/fuse-eap-openshift-jdk11-rhel8@sha256:6f42bc1c86c604b94e01009027d636bdbc35791988de1a226b3e9594f266b743
fuse7/fuse-java-openshift-jdk11-rhel8@sha256:929ffa44c50f18d1f0e2db516d71844074dcf48feee8f415273460c4bb728aea
fuse7/fuse-java-openshift-rhel8@sha256:1880ec68f8494bff263fad41a6b7565b2ad2380de10e79b691f690b0eeb13125
fuse7/fuse-karaf-openshift-jdk11-rhel8@sha256:9a790470f3fa41daa8f2a12476032e866ec097958c7104e05b355ea3132dbf67
fuse7/fuse-karaf-openshift-rhel8@sha256:07e3d973c1f56e3774e9c680ca284a7e68ceb8c12a43416ec473bc4df884cb7f
fuse7/fuse-online-builder-rhel8@sha256:b5857ba91be38cfacf54ed9377c59edab4aeb52910d898cf9474ff7eda6326db
fuse7/fuse-online-meta-rhel8@sha256:e46119d54d084230f4cc6daca7b6d0f3a6bb7d9e0783df023ce70b941349d441
fuse7/fuse-online-rhel8-operator@sha256:5fbf80f61cd54113d8661c40abbdafd107f08fa5bc568f8c4d96de0e28a9206e
fuse7/fuse-online-server-rhel8@sha256:fda16949faa042b0e0567d6c9d4bab99486443a7e32f56f58f5c996b18d3e54d
fuse7/fuse-online-ui-rhel8@sha256:73ed5a87af44951d5071a7d1642c57afbe0e686d60454cdd0a50898cb8fd475d
fuse7/fuse-online-upgrade-rhel8@sha256:f7c9ab206ee8275ea98b2e1f3548a8c22a14d028a6fdf2f65b1e0d36ca7e7b3a
fuse7/fuse-postgres-exporter-rhel8@sha256:5e08a4a4f0aef80969a27e7dfa195267b2a6714d63835168f76d5f70d0fab60b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility