Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2023:1170 - Security Advisory
Issued:
2023-03-08
Updated:
2023-03-08

RHSA-2023:1170 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Data Foundation 4.12.1 security bug fix update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Data Foundation 4.12.1 Bug Fix Update

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multicloud data management service with an S3 compatible API.

Security Fix:

  • goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238)

For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE pages listed in the References section.

Bug fixes:

  • Previously, wrong and unclear error messages were displayed on Failover/Relocate modal. With this fix, appropriate error messages with links to documentation is added to most of the error messages. (BZ#2161903)
  • With this update, the read operations performance of the Multicloud Object Gateway database is improved. To achieve this, a certain regular expressions that are used by some of the queries that run against the database to serve the required data are pre-compiled. This saves time when run in real-time. (BZ#2149861)
  • Previously, the default container created in Azure was with public access enabled. With this fix, the default container created will not have the public access enabled which means `AllowBlobPublicAccess` is set to false. (BZ#2168838)
  • With this update, the `multicluster-orchestrator` operator is listed under the operators supporting disconnected mode installations. To list this operator, the disconnected mode support annotation is added to CSV as the user interface (UI) uses this annotation. (BZ#2166223)

All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 8 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 8 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 8 s390x

Fixes

  • BZ - 2123501 - [RDR] Pod stuck due to error "applyFSGroup failed for vol" for a PVC that was relocated
  • BZ - 2156729 - CVE-2021-4238 goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be
  • BZ - 2159466 - [MDR RDR] Application user unable to invoke Failover and Relocate actions
  • BZ - 2161652 - Namespace store fails to get created via the ODF UI
  • BZ - 2165493 - [MCG] Azure bs/ns creation fails with target bucket does not exists
  • BZ - 2165960 - [4.12.z clone] ocs-operator CSV is missing disconnected env annotation.
  • BZ - 2166220 - [RFE] ODF bluewash introduction in 4.12.x
  • BZ - 2166223 - CSV is missing disconnected env annotation and relatedImages spec
  • BZ - 2167301 - [RFE] ODF bluewash introduction in 4.12.x
  • BZ - 2167950 - CSV is missing disconnected env annotation and relatedImages spec
  • BZ - 2168637 - fix redirect link to operator details page (OCS dashboard)
  • BZ - 2170106 - Update to RHCS 5.3z1 Ceph container image at ODF-4.12.1
  • BZ - 2170449 - Include at ODF 4.12 container images the RHEL8 CVE fix on "libksba"

CVEs

  • CVE-2020-10735
  • CVE-2021-4238
  • CVE-2021-28861
  • CVE-2022-3650
  • CVE-2022-4415
  • CVE-2022-40897
  • CVE-2022-45061
  • CVE-2022-47629

References

  • https://access.redhat.com/security/updates/classification/#important

ppc64le

odf4/cephcsi-rhel8@sha256:2efab7175a812233cef2817135e43e32693a7ca1d1db32751ca87d9ead91c012
odf4/mcg-core-rhel8@sha256:8a1899c5242b816dc9b0d2f2f3d1e4d64297d0a964b0abe0fc6f7062d680696d
odf4/mcg-operator-bundle@sha256:5906155e5fbc72c275c3960187eb0f98b394d11510124268c78e1f0715c976dd
odf4/mcg-rhel8-operator@sha256:e04802904001a781b69a6d454f62a596dbd52e28c45d930da580b2802b71540b
odf4/ocs-metrics-exporter-rhel8@sha256:9ebab5887706c4bc924875c7cea89ae8c6b3db46b76752939ac46803f2f6af17
odf4/ocs-must-gather-rhel8@sha256:7c8106a495b52d76507843258851ac3ad69fb3b45731e4f3159a1dd817f1164a
odf4/ocs-operator-bundle@sha256:c80107419f542f1eea9bee26042e5981f7b113f3d03cc3b6bd90ddcc0df061de
odf4/ocs-rhel8-operator@sha256:b153cd17b1b9ab7f0e94ec780ffcea37f15b5d1df24f00f05fbbbb335cd43325
odf4/odf-console-rhel8@sha256:9d42cc00cbe604e41054f8ed81f63431af20946dd890b97126bf950334283034
odf4/odf-csi-addons-operator-bundle@sha256:4bd266bfe459b5e627547c28a9af878d4116e769f9a13be2072d041d83146eab
odf4/odf-csi-addons-rhel8-operator@sha256:c567a5a4e6458ea21d69b38652313b0e69b3d4bc34c7f42e6129b0110742c20d
odf4/odf-csi-addons-sidecar-rhel8@sha256:de312d578f571539d6c326ac2344536138db3da525d07deb8abf3035404c3d50
odf4/odf-multicluster-console-rhel8@sha256:b95a8e7eb20ad44e27d068db1e9ac0c311da8b61b653ed817a96746c5ac94cb2
odf4/odf-multicluster-operator-bundle@sha256:0cec5466284bc0ad3f56125c6de1c2dd2b8ecc0c692564f3f62c64da06103cd0
odf4/odf-multicluster-rhel8-operator@sha256:2c7a1ff5817ba7ce322ae9267b058b717ad0cf5c2b54888e40e88d07c2ed9e08
odf4/odf-operator-bundle@sha256:c5b1986ed0edfeecda793826630abcdf3b713535e5f1563b5dba271ba6cbd319
odf4/odf-rhel8-operator@sha256:38252327e80581ef4d956f9e078c2dd24584336e35afa3d471a2af1adea7e733
odf4/odr-cluster-operator-bundle@sha256:20e24baf919d7d8e38276a4d76aa4d921d3ba2d5e2021574ac069e1b3662d313
odf4/odr-hub-operator-bundle@sha256:9ca48775685169e6f30e5329d75bef000bbb056568acdd9e83f4f7f222effdc4
odf4/odr-rhel8-operator@sha256:c64f3012e492f536a6a9252abebfdabeff85558a5cb84ec3ec9cac40cd754dcc
odf4/rook-ceph-rhel8-operator@sha256:9fa7008118b8b63c6519d476fee7f1a95c7744e538f2f5528086c9dcb642c081

s390x

odf4/cephcsi-rhel8@sha256:017360949f5393cb3f2943657ca6ccda009e92d7a5eee66b48648384887df896
odf4/mcg-core-rhel8@sha256:44482902e8804533ba6b9bbaee10d822ea6d152b5ef1351d95ee3baf1016ac36
odf4/mcg-operator-bundle@sha256:4a3cf71c771a0a2f0e0010f18ef522ad5dbccb5b4c913b03e4b56c398f96d9ea
odf4/mcg-rhel8-operator@sha256:8acd4192c013076dfe911296121c745be52b672c3e6a9f246d6b4a74907d548f
odf4/ocs-metrics-exporter-rhel8@sha256:61c0eee66abccc097681196c6e9bb5fbe8262fa0be4eaaf127efb39ad00873c1
odf4/ocs-must-gather-rhel8@sha256:4402c949ec76fd18bf1ef1c01ca6b255be638c9e5fc58b5089a6f4daf162753b
odf4/ocs-operator-bundle@sha256:6d0a2f475db0446c4045734fd9d9845be45d4d725fd4c9110cd29d6ff133e27b
odf4/ocs-rhel8-operator@sha256:69538e52ca90e50550aa27b33fce01b033ebd1734e4e73073e844381def16e10
odf4/odf-console-rhel8@sha256:b8c7ac3b4d405fbf50346855818a521f35682b35123efe946fd0bdcd39dadbb9
odf4/odf-csi-addons-operator-bundle@sha256:c9387758cd4e4cab5804574611641150aac6c28464cabc41abf48da86ed797c5
odf4/odf-csi-addons-rhel8-operator@sha256:ac44884a3d8361a25db16b179734804a7d4235c62c36b2b51f490fc11975eb44
odf4/odf-csi-addons-sidecar-rhel8@sha256:d761183fa14e13525bcdb4c7ec4761d268712c31f98b5feff8c3c216d52fae77
odf4/odf-multicluster-console-rhel8@sha256:ec59d876c160b7059a8710eeb95830377ce4635a21bb3db799c00026bae6acf4
odf4/odf-multicluster-operator-bundle@sha256:ede1c74bb294f07ba04b009e18de7bafdece382c95b9068c2ecf248a41d77737
odf4/odf-multicluster-rhel8-operator@sha256:124fec6cc88ca3e28bef04581bbf5e9c4544ada9040ed13d02373afe03c000e7
odf4/odf-operator-bundle@sha256:f74e84a9d0bd2f3aaf84a8cec807911de71c7bca5775638713095bb4ff9d57e1
odf4/odf-rhel8-operator@sha256:beb1e2875d51a1f50ecab12603d1ebff2833148658c09f6a503ff929708fe4f3
odf4/odr-cluster-operator-bundle@sha256:d5e89e8b81e0bf5129aaf84bcf2b8dbe27edea8f0637c709475c25b7d0a93632
odf4/odr-hub-operator-bundle@sha256:bd2a3ccb56eac444cdbe0a327d63606353cba0771f1904ea26b1410750ac14df
odf4/odr-rhel8-operator@sha256:5805078caef433633426dc04e19da1352af738894c17c2a8124f2f2b3522f7b9
odf4/rook-ceph-rhel8-operator@sha256:c6c33e9c8f818ffadf2288b00ba9fb1613634be5d441078ef884fec43a3c77f3

x86_64

odf4/cephcsi-rhel8@sha256:88ea4a7062bcc3226d149f407001986403af241d36c08545aa6c99d6cfeab663
odf4/mcg-core-rhel8@sha256:e2bf8bf0a03396f1e1d070b4e92351f13f5220faae12630ebced74d94867dd59
odf4/mcg-operator-bundle@sha256:cf0bf970b15f99e6a80d0294df07cd8805844e51692b30ef2e3c060b0bc61391
odf4/mcg-rhel8-operator@sha256:dd51f4ef6b54c52461ad1e6b0a4fa3862688cdaaed9440a1b334f1cc0f03d005
odf4/ocs-metrics-exporter-rhel8@sha256:2d106191626257e1144464a85470f95f188ef83f68a874cde49eab6c1b580ad6
odf4/ocs-must-gather-rhel8@sha256:13cab9e402129ec2a35ffd7ec4681b1d916db15b1cec77fd4979f27d7e8b7a97
odf4/ocs-operator-bundle@sha256:4f21b0103684374c404c42cf19a070fc23c8121a85b596bf2594db86dd360416
odf4/ocs-rhel8-operator@sha256:02df4dd9edab9ff6b775039a2380a644ce656036567d73d11333ea7a7a1e8ee1
odf4/odf-console-rhel8@sha256:54846e3ca5ddb5e4ae32eb7b4fc09399ebcd03ee82070cfefb744bf1757460a8
odf4/odf-csi-addons-operator-bundle@sha256:a90da59693ed05b555e4e94a35272b846ad0da97006b19484f265abd437dd290
odf4/odf-csi-addons-rhel8-operator@sha256:93d972a8e2136653d5cd320fbb90231fb2ed009879f742e9e6544c837c8ddb7f
odf4/odf-csi-addons-sidecar-rhel8@sha256:9b48f42cf5dabc673c4a475254de2596eb454d89737b1b1180b2b859d66762b1
odf4/odf-multicluster-console-rhel8@sha256:ca13696105dc0a4ed3db14f2bd1ceef266a53fbae32f4840a9ea57d203b25aa3
odf4/odf-multicluster-operator-bundle@sha256:1718d8b367ecde7364d88fe99c0f2bde30749276007314e416194b58b8e9dcb9
odf4/odf-multicluster-rhel8-operator@sha256:a16b2938681ae705749793ffa7241914814b7f7d2102446441d4e0c2e5ace416
odf4/odf-operator-bundle@sha256:5c7bef8fcb6b4ee1fb845c31d9da687e8901cee3a2f22607a5364ed9e854b305
odf4/odf-rhel8-operator@sha256:4ef7e7d585bfa1b478e3d9c8e6c2b9c78aab5c26349d8b7258316f01b6f03aa2
odf4/odr-cluster-operator-bundle@sha256:084e7de91164387f7a44776838399e2290c922005795a3218b5712fde48debc1
odf4/odr-hub-operator-bundle@sha256:45eee4a07430c555cdfad206be51983c48a51793b9e462d8eaec3657aee387ab
odf4/odr-rhel8-operator@sha256:04761108902c23ba9783b9fa07da94966f685a7cea394b3afae2049b588f2722
odf4/rook-ceph-rhel8-operator@sha256:e49fed746b7b1020721f0227444fbc9880b3b0513d1ece03eb9d5619b246cc53

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter