Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4287 - Security Advisory
Issued:
2023-07-26
Updated:
2023-07-26

RHSA-2023:4287 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Data Foundation 4.12.5 security and bug fix update

Type/Severity

Security Advisory: Moderate

Topic

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.5 on Red Hat Enterprise Linux 8 from Red Hat Container Registry.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multicloud data management service with an S3 compatible API.

Security Fix(es):

  • openshift: OCP & FIPS mode (CVE-2023-3089)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Previously, OpenShift Data Foundation was not setting up the correct user interface (UI) plugin version in its generated `plugin-manifest.json` during the upgrades. This resulted in OpenShift Data Foundation not showing up the refresh pop-up because it could not detect the change in version.

With this fix, the correct plugin version is set up to enable OpenShift Container Platform console to detect upgrades and trigger the refresh pop-up dialog box. As a result, a refresh pop-up shows up and when clicked, it loads the new UI content for the upgraded OpenShift Data Foundation. (BZ#2214575)

  • Previously, in MultiCloud Object Gateway (MCG), there was a significant degradation in performance with read and write operations of small objects. The degradation was because the Remote Procedure Calls (RPC) between the MCG endpoint and the core that were required to be cached missed the cache each time causing an RPC message between the endpoint and the core per each operation.

With this fix, the lookup in cache is fixed so that the existing data is found and not queried at each operation. (BZ#2215978)

  • Previously, there were repeated crashes of the MultiCloud Object Gateway (MCG) Operator because the operator collided with the updates to the structure when it was trying to print a debug message regarding an internal structure in the MCG Operator.

With this release, the print is fixed so that there are no collisions, thereby avoiding the repeated crashes fo MCG Operator. (BZ#2216402)

All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Data Foundation 4 for RHEL 8 x86_64
  • Red Hat OpenShift Data Foundation for IBM Power, little endian 4 for RHEL 8 ppc64le
  • Red Hat OpenShift Data Foundation for IBM Z and LinuxONE 4 for RHEL 8 s390x

Fixes

  • BZ - 2210475 - When collecting Must-gather logs shows /usr/bin/gather_ceph_resources: line 341: jq: command not found
  • BZ - 2211592 - [ODF 4.12] [GSS] unknown parameter name "FORCE_OSD_REMOVAL"
  • BZ - 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode
  • BZ - 2213452 - Set ??maxOpenShiftVersion to block OpenShift that didn't upgrade ODF version
  • BZ - 2214575 - ODF dashboard crashes when OCP and ODF are upgraded
  • BZ - 2216402 - [backport to 4.12.z] noobaa-operator pod shows multiple restarts
  • BZ - 2224246 - [Major Incident] CVE-2023-3089 mcg-operator-container: openshift: OCP & FIPS mode [openshift-data-foundation-4.12]

CVEs

  • CVE-2020-24736
  • CVE-2023-1667
  • CVE-2023-2283
  • CVE-2023-3089
  • CVE-2023-24329
  • CVE-2023-26604

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

ppc64le

odf4/cephcsi-rhel8@sha256:0e9665305bb269c1c0477f7b1937e5e7450f83244a652ff5e5cfe6dd3ca2e23d
odf4/mcg-core-rhel8@sha256:520a18f8943341fdaf36ab044d263934eb533278263a54ed68665a5628f8bb14
odf4/mcg-operator-bundle@sha256:50db58771e5b8fafb5b0892d0322bc0d48ae24ea85719c7ff52f5246befb03bc
odf4/mcg-rhel8-operator@sha256:7286f02997374bb7bbddb2b419bf84d4997010a68400197ae040a76114601e66
odf4/ocs-client-operator-bundle@sha256:605f96551ce408a8f5a8a622cbf289e2b970d638e14c69c6a258eee24943faa0
odf4/ocs-client-rhel8-operator@sha256:903d904a07760ac3e54cdfc97a7f638e0554b64a0e0bb3abd04a6345585ed60f
odf4/ocs-metrics-exporter-rhel8@sha256:8e44e9f85346c28ba5272fb79c38cee6d721170e71a0d73aff799db0e9a5c4b0
odf4/ocs-must-gather-rhel8@sha256:89c7dd0671714a697f2672734eaec29e3b3271d5d4f3a281ec553d0ffd690ceb
odf4/ocs-operator-bundle@sha256:a1ff9195f43b64078346c56086daf33af532af4c2495b2a28cded6aeb6186b64
odf4/ocs-rhel8-operator@sha256:fa154fadad5a1f4739baa1ae234619f68dd1ca2f7edde2478f7ae34120b798d9
odf4/odf-console-rhel8@sha256:b797cba04c643ea07f06cadff809d9f97d0cd993eec72625b96a7a2b5cbd6cb7
odf4/odf-csi-addons-operator-bundle@sha256:ff5f057e85c3de3671bcdf45b9e6a1de9b7db47fdf4be7afdff2eb5dfd61fd29
odf4/odf-csi-addons-rhel8-operator@sha256:a075cd11d3aa0b7564d72263653e20def8e3b6a1af9c1fa54838c7bf83c89cfa
odf4/odf-csi-addons-sidecar-rhel8@sha256:11ed957dc1b1763dc597fe85a7b600d6fac34a22aacb1932b6887e17e198e51a
odf4/odf-multicluster-console-rhel8@sha256:e8fd496f9272874325796bfc072bd01adb81394f8e6ff33d3f003d432d3f1fcd
odf4/odf-multicluster-operator-bundle@sha256:50d1934e7a619b10f7e66e61685beb9938120d03786c85b31273cad837d1ac43
odf4/odf-multicluster-rhel8-operator@sha256:e60bc2f7f9e659f78a5f55c39a03224e53861a24c95aac44e091e5dd8adae6dc
odf4/odf-operator-bundle@sha256:e67c325de7727ff39f8782e52d24cf48ae7a68822c103af4ada51e0e21d17c49
odf4/odf-rhel8-operator@sha256:fddbed6f728f6c6e79c295ad10a2122174dcb221177a3a7335a230fdc7dfdd5e
odf4/odr-cluster-operator-bundle@sha256:79281810e525ee29f6ccbdf34bc60d8358ceb4754f6519ac57e9564ab075cc21
odf4/odr-hub-operator-bundle@sha256:b9bb79f4e1716b1f921e841aea254f02abda32ea897ff59323d267f77cf5f16c
odf4/odr-rhel8-operator@sha256:061e9b95f8f00112a2599cd2304d2003eac763b1d628ec4a626845a3a2b26dba
odf4/rook-ceph-rhel8-operator@sha256:610fc1e02673e8a2a60d068e7310df97550c9ddfb147a0d222f720e3de25bb42

s390x

odf4/cephcsi-rhel8@sha256:77ee77ad74a3eff227bff0a3692830c03940a7250c19fa2348e1ef840c7af30b
odf4/mcg-core-rhel8@sha256:4413daedf7091b63f3a89ee4432837b45babbe58a77c463537ded2ea6a9467ce
odf4/mcg-operator-bundle@sha256:5f0d2305e07bf0a7d5f75fef18b31ff60e614a86381c84b6280c1c9c43119086
odf4/mcg-rhel8-operator@sha256:6032ab00ea6e4a56187cab1b4be920a88f82f70264239e555180f5440c6d3975
odf4/ocs-client-operator-bundle@sha256:2d84da5f868634b1b821f835ede095a125c383b7dcce64eaa4f2df377abba659
odf4/ocs-client-rhel8-operator@sha256:6b51038416f463d7a960f813ae96ae4045f8c3725f2030de8357f1b56efc82d0
odf4/ocs-metrics-exporter-rhel8@sha256:e736261857d225e5e370b932f4028d8bc4b494cfc3400577890f796b83bc18f3
odf4/ocs-must-gather-rhel8@sha256:cde2dd5654090eb265d2e3e38c4a5a1a1f45efa56150fd2c5bb1a2680ec6e07d
odf4/ocs-operator-bundle@sha256:2958d91d83828595e729b0581b6db7a8c0e84e0b631061c3b6ebe1d7fd597202
odf4/ocs-rhel8-operator@sha256:4d2afb4cded09378a16c170c8c15593d8e375bc34993e56744156fc0877a9c01
odf4/odf-console-rhel8@sha256:d68673900dc41402ab9d41335007bbda8798ab3acb25716083d14e88139e55cf
odf4/odf-csi-addons-operator-bundle@sha256:a466eccbeefcd2d194f47c55e02d253a641ea62416e63f40c9116e26cd490bc5
odf4/odf-csi-addons-rhel8-operator@sha256:aef3c4d4cd76c1ffdca09571265c88b13ed764bd3f21a2f2c3a4970c6f562938
odf4/odf-csi-addons-sidecar-rhel8@sha256:4cb991a1fb053108110c5200f236f019f1506a87d8fe5aea9deba96fe23f70e2
odf4/odf-multicluster-console-rhel8@sha256:73c70b0cd2c5370c7682b9072670caad1fec5fbe2bdc985ac03624293eed6405
odf4/odf-multicluster-operator-bundle@sha256:647d9364a7732b8c0e0dd397e216432ee3f9afa9a7d925cd4441125af9428afd
odf4/odf-multicluster-rhel8-operator@sha256:4bc1063a476397892e461edd20d77b5c669cc715a8b789a6b85fdbd39ef11f22
odf4/odf-operator-bundle@sha256:ce6b69715105b2436e3b991387d69b9123e0afb3316af6212114df14c3f1517e
odf4/odf-rhel8-operator@sha256:a000342a018fe556cc52037fbef2ed79197ffc9e1c30d7cf747096945bd72d86
odf4/odr-cluster-operator-bundle@sha256:8df140df17a43538b9c41ed8b0d6a393b7ec6059ff54a027a0aeb5a6dce822f5
odf4/odr-hub-operator-bundle@sha256:f019e4cbf19b3d2af2b6ba9b8d8b38651f348b9b6a70017d69733a686922f2d2
odf4/odr-rhel8-operator@sha256:be9de85481120c6f295343077a6a411ceb244568b8edb5be69283bad0f3b9c80
odf4/rook-ceph-rhel8-operator@sha256:8aa7dcc63927d1b5f9e083a54bb30052b181f67c5aa97ea7ae44316eb1fe18e5

x86_64

odf4/cephcsi-rhel8@sha256:62a40dd80a9128b47fe4f29295a67a1b83c3956fc9836e1b93d0dfe3c955d910
odf4/mcg-core-rhel8@sha256:e60ddab293fee3da7546828da66454d380e1700848eb03df389f9f8596ff1d9c
odf4/mcg-operator-bundle@sha256:ff1360c996eb7309ff029f630baa8178242a148c49ebe3cb4d56d9a78b1f1a9e
odf4/mcg-rhel8-operator@sha256:c567fb57805dd567f07ea715c9ea1d02f889a1605d4796868427d6172aab5d6e
odf4/ocs-client-operator-bundle@sha256:64e7dd5e6bf081c9f2b5e420ada0cdffbe93dc5ac5fa605506a604abbc800be6
odf4/ocs-client-rhel8-operator@sha256:aa0c199ff0e602a852886b5429f1c8ccd14d82586e58b31ac2463bf917bfcb43
odf4/ocs-metrics-exporter-rhel8@sha256:077701042c10985ad3cc178abcdf066ded13007f3580cb735e76a3c307dc3624
odf4/ocs-must-gather-rhel8@sha256:b66d0a01dc8deabdd7863066a2c56b69d6e66e9da0ce1725b5a29075b8a83d89
odf4/ocs-operator-bundle@sha256:e3c020b667022dc56e9bed23497c450544e50a69561abb56ae34503bc5f519e7
odf4/ocs-rhel8-operator@sha256:5f2e22224ebef56cb06ffb38982098ab7b5dc633014c2bb05626cdb47d9b7c33
odf4/odf-console-rhel8@sha256:feb55ff559f5d8a4ade333b15aca4dff7627e707b2457ca94ec0564c09325eca
odf4/odf-csi-addons-operator-bundle@sha256:3e800b8d04bcc237536ab6036d02215a8a496d4a156d1c928f2f9a25b5186a9b
odf4/odf-csi-addons-rhel8-operator@sha256:2a1e40344cb3a91f6dcac8b7d8f2797e2a4e48ac3096a6c42a7b1af0054b9c61
odf4/odf-csi-addons-sidecar-rhel8@sha256:a0a11f8972af10935811a051432a470b8385247c857339fb8f1e3c97aef97c27
odf4/odf-multicluster-console-rhel8@sha256:cecf7d1cc8e7028a5e389fbb56067f9651fe7a91a21dc1f70a55bde226b20c63
odf4/odf-multicluster-operator-bundle@sha256:f469afe7d3473064548eb15f11acb02ada834821cd91b29fbd6c1e2dd0c922df
odf4/odf-multicluster-rhel8-operator@sha256:e98dfab79302f0eebeee3383a285626ab3eb1c1a797fe03cc682db119dcc5a28
odf4/odf-operator-bundle@sha256:0e056b48bc911d6005197e5ecaee2f205391c2a0b8116223b7fa88634d4cd4dd
odf4/odf-rhel8-operator@sha256:6ae23febf11afb876ef8971c6ba3ec9897b8c58b96db0c61d18c5f182e061986
odf4/odr-cluster-operator-bundle@sha256:15595abb25b23878802333a7ba7e787d0ad6198dcb262c9c8611589d73d59e56
odf4/odr-hub-operator-bundle@sha256:cf62007428b8b9e27b70ee9baebabcae01f7b6841779eabe97e35806b6c5d1b9
odf4/odr-rhel8-operator@sha256:c115a7ecd3147b4abb475cf30c6b58ae4e84d65884c9f8cd22111d2b129c680d
odf4/rook-ceph-rhel8-operator@sha256:e6dd8757d9509ba8129d893b1fcf119098d2601b8f02cc12603762db2ce528d3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
2023
  • Privacy Statement
  • Terms of Use
  • All Policies and Guidelines
We've updated our <a href='http://www.redhat.com/en/about/privacy-policy' class='privacy-policy'>Privacy Statement</a> effective September 15, 2023.
Red Hat Summit Red Hat Summit
Twitter