Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2021:3820 - Security Advisory
Issued:
2021-10-19
Updated:
2021-10-19

RHSA-2021:3820 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: OpenShift Container Platform 4.8.15 packages and security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Red Hat OpenShift Container Platform release 4.8.15 is now available with
updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.8.15. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHBA-2021:3821

Security Fix(es):

  • jenkins: improper permission checks allow canceling queue items and aborting builds (CVE-2021-21670)
  • jenkins: session fixation vulnerability (CVE-2021-21671)
  • golang: net: lookup functions may return invalid host names (CVE-2021-33195)
  • golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)
  • golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)
  • golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.8 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-between-minor.html#understanding-upgrade-channels_updating-cluster-between-minor.

Solution

For OpenShift Container Platform 4.8 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html

Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.8 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform 4.8 for RHEL 7 x86_64
  • Red Hat OpenShift Container Platform for Power 4.8 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.8 for RHEL 8 s390x

Fixes

  • BZ - 1983596 - CVE-2021-34558 golang: crypto/tls: certificate of wrong type is causing TLS client to panic
  • BZ - 1989564 - CVE-2021-33195 golang: net: lookup functions may return invalid host names
  • BZ - 1989570 - CVE-2021-33197 golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty
  • BZ - 1989575 - CVE-2021-33198 golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents
  • BZ - 2007749 - CVE-2021-21670 jenkins: improper permission checks allow canceling queue items and aborting builds
  • BZ - 2007750 - CVE-2021-21671 jenkins: session fixation vulnerability
  • BZ - 2013510 - Placeholder bug for OCP 4.8.0 rpm release

CVEs

  • CVE-2021-21670
  • CVE-2021-21671
  • CVE-2021-33195
  • CVE-2021-33197
  • CVE-2021-33198
  • CVE-2021-34558

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 4.8 for RHEL 8

SRPM
butane-0.12.1-2.rhaos4.8.el8.src.rpm SHA-256: 6b832ccf80c5f4c351300d83b2cb5508bcab670191f7a9b0b366494327644366
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el8.src.rpm SHA-256: e5e5d1bbc4ebaeb3db1f7246c21d0450fbf79e0b7ed0cdad22328696ed7d508b
jenkins-2-plugins-4.8.1633555500-1.el8.src.rpm SHA-256: c057c7a46fff8fe671d94db9aca04fe760b4e0417ef047855fdea188ab69e521
jenkins-2.289.3.1633554819-1.el8.src.rpm SHA-256: a0b14d429df7f83791d5aa210a0a73c8137575216bc07c31cf50118e7f763999
ovn2.13-20.12.0-140.el8fdp.src.rpm SHA-256: 63df36c0551532b21e7b2968e5b5568d4d24bb3bfcfcc68cb4f16bad6b6ae5a1
x86_64
butane-0.12.1-2.rhaos4.8.el8.x86_64.rpm SHA-256: 7737c7b73048a291d45d36ad2cb8190f42d58180dc1ff6034b8667dad7246a24
butane-debuginfo-0.12.1-2.rhaos4.8.el8.x86_64.rpm SHA-256: 9395df3c8c49056fce6dd5e19d85b92f445993a79189dcfcfc6688c79e03b745
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el8.x86_64.rpm SHA-256: 8115ce512a501055a95608115388bc36240e3f7d117b0afeacfd44334a4b7d05
cri-o-debuginfo-1.21.3-6.rhaos4.8.gite34bf50.el8.x86_64.rpm SHA-256: 3b7374769669e94d6f3ba7fa373f81e1f0f8f3b2a059b50ad6c7efc256a3ae5a
cri-o-debugsource-1.21.3-6.rhaos4.8.gite34bf50.el8.x86_64.rpm SHA-256: cc83bbe34563f62c2f3cd8db69ef524b1af3abde25b568c28d9331aff8d905c3
jenkins-2-plugins-4.8.1633555500-1.el8.noarch.rpm SHA-256: 2ea0f983c47063b62393aad981cd4ea54399b07c99c5c2151a21ebead1c818fa
jenkins-2.289.3.1633554819-1.el8.noarch.rpm SHA-256: 385a8af8d665e48679d3fc32802ba740be232dd4f311a6ae3fde6e9630e9651b
ovn2.13-20.12.0-140.el8fdp.x86_64.rpm SHA-256: 1adba76068b02f1e3f928e2d2c87f4338481a3501ea64a61e6a07c776d77aed0
ovn2.13-central-20.12.0-140.el8fdp.x86_64.rpm SHA-256: ea62cb7607bf46b46a5e3fc8f9dcfdf0d391966096dcb31d226071386dc2a87e
ovn2.13-central-debuginfo-20.12.0-140.el8fdp.x86_64.rpm SHA-256: 7e2bccd5b51b16f1e147d6c32af088b13013f256cae6acaa8839fae84e1dda95
ovn2.13-debuginfo-20.12.0-140.el8fdp.x86_64.rpm SHA-256: ebd86debb03685f17f386461332d796f64801eff24f306449cd152fdb125d035
ovn2.13-debugsource-20.12.0-140.el8fdp.x86_64.rpm SHA-256: fb3e22972f1c2674275072fab5a174de644497a574876aac57c574b773f19261
ovn2.13-host-20.12.0-140.el8fdp.x86_64.rpm SHA-256: db85265ba270d561df171d6b2d49c2d26aa8a57c52ecd7f19fdb12a5e30651c0
ovn2.13-host-debuginfo-20.12.0-140.el8fdp.x86_64.rpm SHA-256: 35d86a655383bf431a97a6c4e72d2864ca179156126a49f83d2d75ed11dd1232
ovn2.13-vtep-20.12.0-140.el8fdp.x86_64.rpm SHA-256: c7ac07b8a2f2887be4fe3ade19112fe62959258383e8889eb4c4c83f07491b38
ovn2.13-vtep-debuginfo-20.12.0-140.el8fdp.x86_64.rpm SHA-256: 451cdf65f5cfef108e93686a36577f7fc0e655828248833e63f71423072c5b68

Red Hat OpenShift Container Platform 4.8 for RHEL 7

SRPM
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el7.src.rpm SHA-256: 1d8af3ad8f419bcc22dfef0afe39de939fb708ed1dd4422db935a9ed899a4bb3
openshift-ansible-4.8.0-202109241839.p0.git.4bb45f8.assembly.stream.el7.src.rpm SHA-256: d80da456b57c1d8ff8deceb33a58039b240f39d31ddb253e2cbad997548560e7
x86_64
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el7.x86_64.rpm SHA-256: b663b67dd770eef650c0bd54ef9b9f5d98af9b3c034744d51d494a819b8f66b3
cri-o-debuginfo-1.21.3-6.rhaos4.8.gite34bf50.el7.x86_64.rpm SHA-256: 64d6bc99a1c33e66824baf7845810f79c25988055846c52ffc0b808b1af14bdc
openshift-ansible-4.8.0-202109241839.p0.git.4bb45f8.assembly.stream.el7.noarch.rpm SHA-256: 68b0fc9c0f694a50372b9a32631b93a986e814e16da3f9bac3490bbef9119536
openshift-ansible-test-4.8.0-202109241839.p0.git.4bb45f8.assembly.stream.el7.noarch.rpm SHA-256: 1ca1571fa628c0f5ac6d8418b4c28896c6f81aad9314861b47bd2ec9eedfbada

Red Hat OpenShift Container Platform for Power 4.8 for RHEL 8

SRPM
butane-0.12.1-2.rhaos4.8.el8.src.rpm SHA-256: 6b832ccf80c5f4c351300d83b2cb5508bcab670191f7a9b0b366494327644366
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el8.src.rpm SHA-256: e5e5d1bbc4ebaeb3db1f7246c21d0450fbf79e0b7ed0cdad22328696ed7d508b
jenkins-2-plugins-4.8.1633555500-1.el8.src.rpm SHA-256: c057c7a46fff8fe671d94db9aca04fe760b4e0417ef047855fdea188ab69e521
jenkins-2.289.3.1633554819-1.el8.src.rpm SHA-256: a0b14d429df7f83791d5aa210a0a73c8137575216bc07c31cf50118e7f763999
ovn2.13-20.12.0-140.el8fdp.src.rpm SHA-256: 63df36c0551532b21e7b2968e5b5568d4d24bb3bfcfcc68cb4f16bad6b6ae5a1
ppc64le
butane-0.12.1-2.rhaos4.8.el8.ppc64le.rpm SHA-256: 824cf2542303689643abd29e0a6b7d4227f58fcc6cddecbb45ec6eef605af06e
butane-debuginfo-0.12.1-2.rhaos4.8.el8.ppc64le.rpm SHA-256: 675889b37c653a2b386bb8729dd90de9fe99a287e25bca0381ce935e5780e677
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el8.ppc64le.rpm SHA-256: c17788ee6ce11c1c7b23679a61fe06fbe11a61debc1cca78dbfb9b1a168dbea3
cri-o-debuginfo-1.21.3-6.rhaos4.8.gite34bf50.el8.ppc64le.rpm SHA-256: b4413c4917fc66fd11c798d4512053eaa524a9cf042b41266ee7283dcfaac472
cri-o-debugsource-1.21.3-6.rhaos4.8.gite34bf50.el8.ppc64le.rpm SHA-256: 58b47b7b8c645838c32403d10f76eded6a19ec8436cd7a1710d06d824da61d62
jenkins-2-plugins-4.8.1633555500-1.el8.noarch.rpm SHA-256: 2ea0f983c47063b62393aad981cd4ea54399b07c99c5c2151a21ebead1c818fa
jenkins-2.289.3.1633554819-1.el8.noarch.rpm SHA-256: 385a8af8d665e48679d3fc32802ba740be232dd4f311a6ae3fde6e9630e9651b
ovn2.13-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 1ced7527fd9de8adc33de5bd5a006366381cd8b595787f9b1032eff9d9dcab65
ovn2.13-central-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 9a25c94ccc2007eeab8c07dbb99df479c1f37b446972db91e53eba8c8e34cb8d
ovn2.13-central-debuginfo-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 533a1f3c6294a0be404d3f9fa4737320db628e4d82ea99dd97a4aae7b1346a67
ovn2.13-debuginfo-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: d4f29feebee96ee86eff47f0903957977de8a93e8cb51e6db0ce1fc8d49cafb1
ovn2.13-debugsource-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 91680da26f768d9d5ac711f0d8bdee6dca4aff2b1188f60c75918f7557e41dbb
ovn2.13-host-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 5a55053219faf00b76b8cbc546404b7ef3a408565c92aa0251890eba625a4a3f
ovn2.13-host-debuginfo-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 4eaaa680e3c66f04ee15ce99f57c66c7ddf8119656bbf4c8dc6db1b797ae3e8b
ovn2.13-vtep-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 4af168f2411ec919c6d7dee81c68d827fe475e6023b1614bd26d1a5eeafe245d
ovn2.13-vtep-debuginfo-20.12.0-140.el8fdp.ppc64le.rpm SHA-256: 1a3878d427aa4313835cdbf67433c4653fcb522e9250e43cc6483c36ff2e41de

Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.8 for RHEL 8

SRPM
butane-0.12.1-2.rhaos4.8.el8.src.rpm SHA-256: 6b832ccf80c5f4c351300d83b2cb5508bcab670191f7a9b0b366494327644366
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el8.src.rpm SHA-256: e5e5d1bbc4ebaeb3db1f7246c21d0450fbf79e0b7ed0cdad22328696ed7d508b
jenkins-2-plugins-4.8.1633555500-1.el8.src.rpm SHA-256: c057c7a46fff8fe671d94db9aca04fe760b4e0417ef047855fdea188ab69e521
jenkins-2.289.3.1633554819-1.el8.src.rpm SHA-256: a0b14d429df7f83791d5aa210a0a73c8137575216bc07c31cf50118e7f763999
ovn2.13-20.12.0-140.el8fdp.src.rpm SHA-256: 63df36c0551532b21e7b2968e5b5568d4d24bb3bfcfcc68cb4f16bad6b6ae5a1
s390x
butane-0.12.1-2.rhaos4.8.el8.s390x.rpm SHA-256: 25bb7bf0c26a6b0b3d289b65aff29c6a08353a6037c44969c869330c8056f933
butane-debuginfo-0.12.1-2.rhaos4.8.el8.s390x.rpm SHA-256: 00e069eb272630b275f98fee995562c9e4bac356f4d008075c8723296d52a792
cri-o-1.21.3-6.rhaos4.8.gite34bf50.el8.s390x.rpm SHA-256: e791e115641a7fa14e3fb9ee5e1bbefd5cdc5ff96b52b878a88f80ad68e533d6
cri-o-debuginfo-1.21.3-6.rhaos4.8.gite34bf50.el8.s390x.rpm SHA-256: 68a85581e75f37378b6dd429411937dcd2e6dc83deb6722581263584265c6c7d
cri-o-debugsource-1.21.3-6.rhaos4.8.gite34bf50.el8.s390x.rpm SHA-256: de507f481ae709dce55b2d0a06dcb7decad337af910bd7fe2b8984ab64d4b373
jenkins-2-plugins-4.8.1633555500-1.el8.noarch.rpm SHA-256: 2ea0f983c47063b62393aad981cd4ea54399b07c99c5c2151a21ebead1c818fa
jenkins-2.289.3.1633554819-1.el8.noarch.rpm SHA-256: 385a8af8d665e48679d3fc32802ba740be232dd4f311a6ae3fde6e9630e9651b
ovn2.13-20.12.0-140.el8fdp.s390x.rpm SHA-256: bdb4582f88ab93ae0e251f152d9e3e0f154a3c769ee478f645b5d923e19d800b
ovn2.13-central-20.12.0-140.el8fdp.s390x.rpm SHA-256: f63586674874a6727cdec2ca75d5abf16df8b2db96d220b84929443f185bb937
ovn2.13-central-debuginfo-20.12.0-140.el8fdp.s390x.rpm SHA-256: c48472edbf8284dea4b1ec7884f5e82b213103161fbb1c00941617ef701ed767
ovn2.13-debuginfo-20.12.0-140.el8fdp.s390x.rpm SHA-256: 42de5e0f2e4159feac48c3514348a004ae8207ac0233210b7c9d1a38edfb5c87
ovn2.13-debugsource-20.12.0-140.el8fdp.s390x.rpm SHA-256: 202ff602f279a6836128bff940f2f7ffda95a931054daad1a0de98fdb936823e
ovn2.13-host-20.12.0-140.el8fdp.s390x.rpm SHA-256: b7d22937f63fc0e209d2f29431c977e653464bfc7bcf319ed0d87ed6e4fc0f24
ovn2.13-host-debuginfo-20.12.0-140.el8fdp.s390x.rpm SHA-256: a902e142dcd2dd01b213feb10fa3f868dbd824f5316a0d318decaf76b8420d20
ovn2.13-vtep-20.12.0-140.el8fdp.s390x.rpm SHA-256: daf940aac7f9ca1ba1aa7aef3251e0c0ecbe42de8855dc85f27c6a249ff0ea46
ovn2.13-vtep-debuginfo-20.12.0-140.el8fdp.s390x.rpm SHA-256: ba8a251aff96704157e46bc6b1c632506ab2a2953d701b435e4a628ea098f138

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter