- Issued:
- 2022-07-20
- Updated:
- 2022-07-20
RHSA-2022:5673 - Security Advisory
Synopsis
Important: Release of containers for OSP 16.2.z director operator tech preview
Type/Severity
Security Advisory: Important
Topic
Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview.
Description
Release osp-director-operator images
Security Fix(es):
- go-getter: unsafe download (issue 1 of 3) [Important] (CVE-2022-30321)
- go-getter: unsafe download (issue 2 of 3) [Important] (CVE-2022-30322)
- go-getter: unsafe download (issue 3 of 3) [Important] (CVE-2022-30323)
- go-getter: command injection vulnerability [Important] (CVE-2022-26945)
- golang.org/x/crypto: empty plaintext packet causes panic [Moderate] (CVE-2021-43565)
- containerd: insufficiently restricted permissions on container root and plugin directories [Moderate] (CVE-2021-41103)
Solution
OSP 16.2 Release - OSP Director Operator Containers tech preview
Affected Products
- Red Hat OpenStack 16.2 x86_64
Fixes
- BZ - 2011007 - CVE-2021-41103 containerd: insufficiently restricted permissions on container root and plugin directories
- BZ - 2030787 - CVE-2021-43565 golang.org/x/crypto: empty plaintext packet causes panic
- BZ - 2092918 - CVE-2022-30321 go-getter: unsafe download (issue 1 of 3)
- BZ - 2092923 - CVE-2022-30322 go-getter: unsafe download (issue 2 of 3)
- BZ - 2092925 - CVE-2022-30323 go-getter: unsafe download (issue 3 of 3)
- BZ - 2092928 - CVE-2022-26945 go-getter: command injection vulnerability
CVEs
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.