Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2020:2992 - Security Advisory
Issued:
2020-07-27
Updated:
2020-07-27

RHSA-2020:2992 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: OpenShift Container Platform 3.11 security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for atomic-openshift, atomic-openshift-web-console, and cri-o is now available for Red Hat OpenShift Container Platform 3.11.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

  • cri-o: A flaw was found in cri-o that can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. (CVE-2019-14891)
  • nodejs-minimist: Prototype pollution allows adding or modifying properties of Object.prototype using a `constructor` or `__proto__` payload. (CVE-2020-7598)
  • kubernetes: Use of unbounded 'client' label in apiserver_request_total allows repeated, crafted HTTP requests to exhaust available memory and cause a crash. (CVE-2020-8552)
  • kubernetes: A flaw was found in Kubernetes that allows attackers on adjacent networks to reach services exposed on localhost ports and gain privileges or access confidential information for any services listening on localhost ports that are not protected by authentication. (CVE-2020-8558)
  • proglottis/gpgme: A use-after-free vulnerability was found in the Go GPGME wrapper library, github.com/proglottis/gpgme. (CVE-2020-8945)
  • openshift/console: A flaw allowed text injection on error pages with a crafted URL. (CVE-2020-10715)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

See the following documentation, which will be updated shortly for release
3.11.z, for important instructions on how to upgrade your cluster and fully
apply this asynchronous errata update:

https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html

This update is available via the Red Hat Network. Details on how to use the
Red Hat Network to apply this update are available at
https://access.redhat.com/articles/11258.

Affected Products

  • Red Hat OpenShift Container Platform 3.11 x86_64
  • Red Hat OpenShift Container Platform for Power 3.11 ppc64le

Fixes

  • BZ - 1767665 - CVE-2020-10715 openshift/console: text injection on error page via crafted url
  • BZ - 1772280 - CVE-2019-14891 cri-o: infra container reparented to systemd following OOM Killer killing it's conmon
  • BZ - 1795838 - CVE-2020-8945 proglottis/gpgme: Use-after-free in GPGME bindings during container image pull
  • BZ - 1797909 - CVE-2020-8552 kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion
  • BZ - 1813344 - CVE-2020-7598 nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload
  • BZ - 1843358 - CVE-2020-8558 kubernetes: node localhost services reachable via martian packets

CVEs

  • CVE-2019-14891
  • CVE-2020-7598
  • CVE-2020-8552
  • CVE-2020-8558
  • CVE-2020-8945
  • CVE-2020-10715

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 3.11

SRPM
atomic-openshift-3.11.248-1.git.0.92ee8ac.el7.src.rpm SHA-256: d55ca1c820a3122fe8ca16674f9dfec7d4c3ea2b2f1489cfd78d54256eb44a48
atomic-openshift-web-console-3.11.248-1.git.1.cc96c2d.el7.src.rpm SHA-256: 796d967c146343c2c9aa3f375bd5e428a911e92fff95419a37f8f3b9df1a0bc8
cri-o-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.src.rpm SHA-256: 82d5379208e73d2810230c2e450c6bc4018c1be2e72970839406a0562afd9988
x86_64
atomic-openshift-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: 5d5faaee48c550bc3b28e473992052cd8d4ce419dfcccba369ad6c9d45ee6137
atomic-openshift-clients-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: d624b6b414cb839e61abf3bf16b4b335bc2d778e57e119e7ed3af1398ecc5643
atomic-openshift-clients-redistributable-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: a158c33fa26674a6e8166c66ead06930b4028ab879ecd42b98a8c9faa3cf0c8f
atomic-openshift-docker-excluder-3.11.248-1.git.0.92ee8ac.el7.noarch.rpm SHA-256: 3dcb49ae91e1ff63ea7222daa907032bbc9c51a77970e40e7b9ca00116a7a26c
atomic-openshift-excluder-3.11.248-1.git.0.92ee8ac.el7.noarch.rpm SHA-256: 24445c4f64318ff7b3615cc1b44b49b467751a3c3459b4a0c570a26f0c14f9cc
atomic-openshift-hyperkube-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: e6cb85887c6715c58267ea1de739020ffaa61a79d62e7518eea97785f90b5a95
atomic-openshift-hypershift-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: 92513a6ae1e85362a23e2eb150db4c81b35c238ed56a1517cf5b62fda63368a2
atomic-openshift-master-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: 3966573d2153cd22258f735dabf72386de799fa3e982ff6fd66eb4bc39ec7bf9
atomic-openshift-node-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: 388a5dec9aae39147205292be81bdd2b72a6f3597e07706084f5e98fa3e044cf
atomic-openshift-pod-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: 3cf098c2a9d697df5f3f3e496de2f2c2e4e7974b13d216344da36f20cd512bd4
atomic-openshift-sdn-ovs-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: bbe9d4cb326b4c9d6f6afbf2219911658dbd48b5181233bb64b090d388b98eda
atomic-openshift-template-service-broker-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: c79ffb94f783e667a3faa51161c2be665f20b4373ad33a9def268fa83919f256
atomic-openshift-tests-3.11.248-1.git.0.92ee8ac.el7.x86_64.rpm SHA-256: 1cb9b0688a1881f951ce7681ce2e359a8a7c88f5a7dec63bc5be8dc1b5b6b11b
atomic-openshift-web-console-3.11.248-1.git.1.cc96c2d.el7.x86_64.rpm SHA-256: 213bee0551ec95bb6af2196b0eb0a0cf09451d1c89d04c430bd6aa183e071730
cri-o-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.x86_64.rpm SHA-256: 031e3e5d01b34dd456bc195c63cd723d412c98ac9304cfd561dc276f3a657569
cri-o-debuginfo-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.x86_64.rpm SHA-256: a18decb81b6c4418433d053ebb9b3bd7fa950f89de60ee4c75a4b43c7b83abea

Red Hat OpenShift Container Platform for Power 3.11

SRPM
atomic-openshift-3.11.248-1.git.0.92ee8ac.el7.src.rpm SHA-256: d55ca1c820a3122fe8ca16674f9dfec7d4c3ea2b2f1489cfd78d54256eb44a48
atomic-openshift-web-console-3.11.248-1.git.1.cc96c2d.el7.src.rpm SHA-256: 796d967c146343c2c9aa3f375bd5e428a911e92fff95419a37f8f3b9df1a0bc8
cri-o-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.src.rpm SHA-256: 82d5379208e73d2810230c2e450c6bc4018c1be2e72970839406a0562afd9988
ppc64le
atomic-openshift-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 67d626f4f78193b97867e3d09f641b40ae04803d64f20d3db3158640a5cf6cc9
atomic-openshift-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 67d626f4f78193b97867e3d09f641b40ae04803d64f20d3db3158640a5cf6cc9
atomic-openshift-clients-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: ee30561b088e47bb3518a60cf2b656017d092476269455995886b5156219dfee
atomic-openshift-clients-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: ee30561b088e47bb3518a60cf2b656017d092476269455995886b5156219dfee
atomic-openshift-docker-excluder-3.11.248-1.git.0.92ee8ac.el7.noarch.rpm SHA-256: 3dcb49ae91e1ff63ea7222daa907032bbc9c51a77970e40e7b9ca00116a7a26c
atomic-openshift-docker-excluder-3.11.248-1.git.0.92ee8ac.el7.noarch.rpm SHA-256: 3dcb49ae91e1ff63ea7222daa907032bbc9c51a77970e40e7b9ca00116a7a26c
atomic-openshift-excluder-3.11.248-1.git.0.92ee8ac.el7.noarch.rpm SHA-256: 24445c4f64318ff7b3615cc1b44b49b467751a3c3459b4a0c570a26f0c14f9cc
atomic-openshift-excluder-3.11.248-1.git.0.92ee8ac.el7.noarch.rpm SHA-256: 24445c4f64318ff7b3615cc1b44b49b467751a3c3459b4a0c570a26f0c14f9cc
atomic-openshift-hyperkube-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: d7f0244b86e3e296231ba841ef39bb5cfb962ce51836bd45ac632afced6b01fb
atomic-openshift-hyperkube-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: d7f0244b86e3e296231ba841ef39bb5cfb962ce51836bd45ac632afced6b01fb
atomic-openshift-hypershift-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: fb6aa6c9334a431fa313a361c64058052e17a306810d157dd2234a0af3a832bd
atomic-openshift-hypershift-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: fb6aa6c9334a431fa313a361c64058052e17a306810d157dd2234a0af3a832bd
atomic-openshift-master-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 80dcb3066be3795071104d368a8da769536091d6b75bdb83212e25d74695f607
atomic-openshift-master-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 80dcb3066be3795071104d368a8da769536091d6b75bdb83212e25d74695f607
atomic-openshift-node-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: c920b2815b5b301184ffcfa2bec82f4217c64eedf7524aede1c1406b0e09aa85
atomic-openshift-node-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: c920b2815b5b301184ffcfa2bec82f4217c64eedf7524aede1c1406b0e09aa85
atomic-openshift-pod-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 42aadfad256d52aa0c7fd1976c581c760a310770daee0eb5ae82317e667cdd97
atomic-openshift-pod-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 42aadfad256d52aa0c7fd1976c581c760a310770daee0eb5ae82317e667cdd97
atomic-openshift-sdn-ovs-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: d4af688f8d33a10b0272d66606327ee0f943d4fec01777f998fd1fb7ab9cbefe
atomic-openshift-sdn-ovs-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: d4af688f8d33a10b0272d66606327ee0f943d4fec01777f998fd1fb7ab9cbefe
atomic-openshift-template-service-broker-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 417b236f3fb2155078044549d9c01ea671b5fb3cd307b314872ffde37fe6f7d9
atomic-openshift-template-service-broker-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 417b236f3fb2155078044549d9c01ea671b5fb3cd307b314872ffde37fe6f7d9
atomic-openshift-tests-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 52985872eaf8d265eecfbf94d7aa88e22341ca9b05ca05906dbb5276339d3465
atomic-openshift-tests-3.11.248-1.git.0.92ee8ac.el7.ppc64le.rpm SHA-256: 52985872eaf8d265eecfbf94d7aa88e22341ca9b05ca05906dbb5276339d3465
atomic-openshift-web-console-3.11.248-1.git.1.cc96c2d.el7.ppc64le.rpm SHA-256: d9197768bba982839eaf58bd5073b3c3975dcf96b748e368505af4f8a246b47e
atomic-openshift-web-console-3.11.248-1.git.1.cc96c2d.el7.ppc64le.rpm SHA-256: d9197768bba982839eaf58bd5073b3c3975dcf96b748e368505af4f8a246b47e
cri-o-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.ppc64le.rpm SHA-256: 94a65b1f26658be84a883776c553d8dd6ccaa3b61234582e8e7e673ad2974d90
cri-o-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.ppc64le.rpm SHA-256: 94a65b1f26658be84a883776c553d8dd6ccaa3b61234582e8e7e673ad2974d90
cri-o-debuginfo-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.ppc64le.rpm SHA-256: 57dd4339820fc92ef89b4ba7566ed9e057cd29a9854add507a8b767c95c63aea
cri-o-debuginfo-1.11.16-0.10.dev.rhaos3.11.git1eee681.el7.ppc64le.rpm SHA-256: 57dd4339820fc92ef89b4ba7566ed9e057cd29a9854add507a8b767c95c63aea

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter