RHSA-2021:2437
Vulnerability Summary
Timeline
Description
Red Hat Security Advisory: OpenShift Container Platform 4.8.2 packages and security update
CVSS Metrics
- v3.1•HIGH•Score: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Systems
- redhat•afterburn
< 0:5.0.0-1.rhaos4.8.el8
- redhat•afterburn-debuginfo
< 0:5.0.0-1.rhaos4.8.el8
- redhat•atomic-openshift-service-idler
< 0:4.8.0-202106281541.p0.git.39cfc66.assembly.stream.el8
- redhat•butane
< 0:0.12.1-1.rhaos4.8.el8
- redhat•butane-debuginfo
< 0:0.12.1-1.rhaos4.8.el8
- redhat•console-login-helper-messages
< 0:0.20.3-1.rhaos4.8.el8
- redhat•console-login-helper-messages-issuegen
< 0:0.20.3-1.rhaos4.8.el8
- redhat•console-login-helper-messages-profile
< 0:0.20.3-1.rhaos4.8.el8
- redhat•coreos-installer
< 0:0.9.0-6.rhaos4.8.el8
- redhat•coreos-installer-bootinfra
< 0:0.9.0-6.rhaos4.8.el8
- redhat•coreos-installer-bootinfra-debuginfo
< 0:0.9.0-6.rhaos4.8.el8
- redhat•coreos-installer-debuginfo
< 0:0.9.0-6.rhaos4.8.el8
- redhat•coreos-installer-debugsource
< 0:0.9.0-6.rhaos4.8.el8
- redhat•cri-o
< 0:1.21.2-5.rhaos4.8.gitb27d974.el7 | < 0:1.21.2-5.rhaos4.8.gitb27d974.el8
- redhat•cri-o-debuginfo
< 0:1.21.2-5.rhaos4.8.gitb27d974.el7 | < 0:1.21.2-5.rhaos4.8.gitb27d974.el8
- redhat•cri-o-debugsource
< 0:1.21.2-5.rhaos4.8.gitb27d974.el8
- redhat•cri-tools
< 0:1.21.0-2.el7 | < 0:1.21.0-2.el8
- redhat•cri-tools-debuginfo
< 0:1.21.0-2.el7 | < 0:1.21.0-2.el8
- redhat•cri-tools-debugsource
< 0:1.21.0-2.el8
- redhat•haproxy
< 0:2.2.13-1.el7 | < 0:2.2.13-1.el8
- redhat•haproxy-debuginfo
< 0:2.2.13-1.el7
- redhat•haproxy-debugsource
< 0:2.2.13-1.el8
- redhat•ignition
< 0:2.9.0-6.rhaos4.8.el8
- redhat•ignition-debuginfo
< 0:2.9.0-6.rhaos4.8.el8
- redhat•ignition-debugsource
< 0:2.9.0-6.rhaos4.8.el8
- redhat•ignition-validate
< 0:2.9.0-6.rhaos4.8.el8
- redhat•ignition-validate-debuginfo
< 0:2.9.0-6.rhaos4.8.el8
- redhat•ironic-images
< 0:2021.1-20210614.1.el8
- redhat•ironic-images-all
< 0:2021.1-20210614.1.el8
- redhat•ironic-images-ipa-ppc64le
< 0:2021.1-20210614.1.el8
- redhat•ironic-images-ipa-x86_64
< 0:2021.1-20210614.1.el8
- redhat•jenkins
< 0:2.289.1.1624020353-1.el8
- redhat•jenkins-2-plugins
< 0:4.8.1624022417-1.el8
- redhat•kata-containers
< 0:2.1.0-4.el8
- redhat•openshift
< 0:4.8.0-202107161820.p0.git.051ac4f.assembly.stream.el7 | < 0:4.8.0-202107161820.p0.git.051ac4f.assembly.stream.el8
- redhat•openshift-ansible
< 0:4.8.0-202106281541.p0.git.626f7a3.assembly.stream.el7
- redhat•openshift-ansible-test
< 0:4.8.0-202106281541.p0.git.626f7a3.assembly.stream.el7
- redhat•openshift-clients
< 0:4.8.0-202106281541.p0.git.1077b05.assembly.stream.el7 | < 0:4.8.0-202106281541.p0.git.1077b05.assembly.stream.el8
- redhat•openshift-clients-redistributable
< 0:4.8.0-202106281541.p0.git.1077b05.assembly.stream.el7 | < 0:4.8.0-202106281541.p0.git.1077b05.assembly.stream.el8
- redhat•openshift-hyperkube
< 0:4.8.0-202107161820.p0.git.051ac4f.assembly.stream.el7 | < 0:4.8.0-202107161820.p0.git.051ac4f.assembly.stream.el8
- redhat•openshift-kuryr
< 0:4.8.0-202106281541.p0.git.8a4c2d8.assembly.stream.el8
- redhat•openshift-kuryr-cni
< 0:4.8.0-202106281541.p0.git.8a4c2d8.assembly.stream.el8
- redhat•openshift-kuryr-common
< 0:4.8.0-202106281541.p0.git.8a4c2d8.assembly.stream.el8
- redhat•openshift-kuryr-controller
< 0:4.8.0-202106281541.p0.git.8a4c2d8.assembly.stream.el8
- redhat•openstack-ironic
< 1:17.0.4-0.20210713221218.a415e7e.el8
- redhat•openstack-ironic-api
< 1:17.0.4-0.20210713221218.a415e7e.el8
- redhat•openstack-ironic-common
< 1:17.0.4-0.20210713221218.a415e7e.el8
- redhat•openstack-ironic-conductor
< 1:17.0.4-0.20210713221218.a415e7e.el8
- redhat•openstack-ironic-inspector
< 0:10.6.1-0.20210406091336.579f59c.el8
- redhat•openstack-ironic-inspector-api
< 0:10.6.1-0.20210406091336.579f59c.el8
Showing first 50 affected entries in server-rendered view.
References (118)
- https://access.redhat.com/errata/RHSA-2021:2437
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=1918750
- https://bugzilla.redhat.com/show_bug.cgi?id=1921650
- https://bugzilla.redhat.com/show_bug.cgi?id=1937562
- https://bugzilla.redhat.com/show_bug.cgi?id=1940489
- https://bugzilla.redhat.com/show_bug.cgi?id=1947102
- https://bugzilla.redhat.com/show_bug.cgi?id=1947105
- https://bugzilla.redhat.com/show_bug.cgi?id=1954917
- https://bugzilla.redhat.com/show_bug.cgi?id=1958407
- https://bugzilla.redhat.com/show_bug.cgi?id=1959545
- https://bugzilla.redhat.com/show_bug.cgi?id=1978621
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2437.json
- https://access.redhat.com/security/cve/CVE-2021-3114
- https://www.cve.org/CVERecord?id=CVE-2021-3114
- https://nvd.nist.gov/vuln/detail/CVE-2021-3114
- https://groups.google.com/g/golang-announce/c/mperVMGa98w
- https://access.redhat.com/security/cve/CVE-2021-3121
- https://www.cve.org/CVERecord?id=CVE-2021-3121
- https://nvd.nist.gov/vuln/detail/CVE-2021-3121
- https://access.redhat.com/security/cve/CVE-2021-3636
- https://www.cve.org/CVERecord?id=CVE-2021-3636
- https://nvd.nist.gov/vuln/detail/CVE-2021-3636
- https://access.redhat.com/security/cve/CVE-2021-21419
- https://www.cve.org/CVERecord?id=CVE-2021-21419
- https://nvd.nist.gov/vuln/detail/CVE-2021-21419
- https://access.redhat.com/security/cve/CVE-2021-21623
- https://www.cve.org/CVERecord?id=CVE-2021-21623
- https://nvd.nist.gov/vuln/detail/CVE-2021-21623
- https://www.jenkins.io/security/advisory/2021-03-18/#SECURITY-2180
- https://access.redhat.com/security/cve/CVE-2021-21639
- https://www.cve.org/CVERecord?id=CVE-2021-21639
- https://nvd.nist.gov/vuln/detail/CVE-2021-21639
- https://access.redhat.com/security/cve/CVE-2021-21640
- https://www.cve.org/CVERecord?id=CVE-2021-21640
- https://nvd.nist.gov/vuln/detail/CVE-2021-21640
- https://access.redhat.com/security/cve/CVE-2021-21648
- https://www.cve.org/CVERecord?id=CVE-2021-21648
- https://nvd.nist.gov/vuln/detail/CVE-2021-21648
- https://www.jenkins.io/security/advisory/2021-05-11/#SECURITY-2349
- https://access.redhat.com/security/cve/CVE-2021-25735
- https://www.cve.org/CVERecord?id=CVE-2021-25735
- https://nvd.nist.gov/vuln/detail/CVE-2021-25735
- https://groups.google.com/g/kubernetes-security-announce/c/FKAGqT4jx9Y
- https://access.redhat.com/security/cve/CVE-2021-25737
- https://www.cve.org/CVERecord?id=CVE-2021-25737
- https://nvd.nist.gov/vuln/detail/CVE-2021-25737
- https://github.com/kubernetes/kubernetes/issues/102106
- https://groups.google.com/g/kubernetes-security-announce/c/xAiN3924thY
- https://access.redhat.com/security/cve/CVE-2021-20291
- https://bugzilla.redhat.com/show_bug.cgi?id=1939485
- https://www.cve.org/CVERecord?id=CVE-2021-20291
- https://nvd.nist.gov/vuln/detail/CVE-2021-20291
- https://unit42.paloaltonetworks.com/cve-2021-20291/
- https://access.redhat.com/security/cve/CVE-2021-21602
- https://bugzilla.redhat.com/show_bug.cgi?id=1925161
- https://www.cve.org/CVERecord?id=CVE-2021-21602
- https://nvd.nist.gov/vuln/detail/CVE-2021-21602
- https://access.redhat.com/security/cve/CVE-2021-21603
- https://bugzilla.redhat.com/show_bug.cgi?id=1925160
- https://www.cve.org/CVERecord?id=CVE-2021-21603
- https://nvd.nist.gov/vuln/detail/CVE-2021-21603
- https://access.redhat.com/security/cve/CVE-2021-21604
- https://bugzilla.redhat.com/show_bug.cgi?id=1925157
- https://www.cve.org/CVERecord?id=CVE-2021-21604
- https://nvd.nist.gov/vuln/detail/CVE-2021-21604
- https://access.redhat.com/security/cve/CVE-2021-21605
- https://bugzilla.redhat.com/show_bug.cgi?id=1925143
- https://www.cve.org/CVERecord?id=CVE-2021-21605
- https://nvd.nist.gov/vuln/detail/CVE-2021-21605
- https://access.redhat.com/security/cve/CVE-2021-21606
- https://bugzilla.redhat.com/show_bug.cgi?id=1925159
- https://www.cve.org/CVERecord?id=CVE-2021-21606
- https://nvd.nist.gov/vuln/detail/CVE-2021-21606
- https://access.redhat.com/security/cve/CVE-2021-21607
- https://bugzilla.redhat.com/show_bug.cgi?id=1925156
- https://www.cve.org/CVERecord?id=CVE-2021-21607
- https://nvd.nist.gov/vuln/detail/CVE-2021-21607
- https://access.redhat.com/security/cve/CVE-2021-21608
- https://bugzilla.redhat.com/show_bug.cgi?id=1925140
- https://www.cve.org/CVERecord?id=CVE-2021-21608
- https://nvd.nist.gov/vuln/detail/CVE-2021-21608
- https://access.redhat.com/security/cve/CVE-2021-21609
- https://bugzilla.redhat.com/show_bug.cgi?id=1925141
- https://www.cve.org/CVERecord?id=CVE-2021-21609
- https://nvd.nist.gov/vuln/detail/CVE-2021-21609
- https://access.redhat.com/security/cve/CVE-2021-21610
- https://bugzilla.redhat.com/show_bug.cgi?id=1925151
- https://www.cve.org/CVERecord?id=CVE-2021-21610
- https://nvd.nist.gov/vuln/detail/CVE-2021-21610
- https://access.redhat.com/security/cve/CVE-2021-21611
- https://bugzilla.redhat.com/show_bug.cgi?id=1925145
- https://www.cve.org/CVERecord?id=CVE-2021-21611
- https://nvd.nist.gov/vuln/detail/CVE-2021-21611
- https://access.redhat.com/security/cve/CVE-2021-21642
- https://bugzilla.redhat.com/show_bug.cgi?id=1952146
- https://www.cve.org/CVERecord?id=CVE-2021-21642
- https://nvd.nist.gov/vuln/detail/CVE-2021-21642
- https://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2204
- https://access.redhat.com/security/cve/CVE-2021-21643
- https://bugzilla.redhat.com/show_bug.cgi?id=1952148
- https://www.cve.org/CVERecord?id=CVE-2021-21643
- https://nvd.nist.gov/vuln/detail/CVE-2021-21643
- https://www.jenkins.io/security/advisory/2021-04-21/#SECURITY-2254
- https://access.redhat.com/security/cve/CVE-2021-21644
- https://bugzilla.redhat.com/show_bug.cgi?id=1952151
- https://www.cve.org/CVERecord?id=CVE-2021-21644
- https://nvd.nist.gov/vuln/detail/CVE-2021-21644
- https://access.redhat.com/security/cve/CVE-2021-21645
- https://bugzilla.redhat.com/show_bug.cgi?id=1952152
- https://www.cve.org/CVERecord?id=CVE-2021-21645
- https://nvd.nist.gov/vuln/detail/CVE-2021-21645
- https://access.redhat.com/security/cve/CVE-2021-30465
- https://bugzilla.redhat.com/show_bug.cgi?id=1954736
- https://access.redhat.com/security/vulnerabilities/RHSB-2021-004
- https://www.cve.org/CVERecord?id=CVE-2021-30465
- https://nvd.nist.gov/vuln/detail/CVE-2021-30465
- https://github.com/opencontainers/runc/security/advisories/GHSA-c3xm-pvg7-gh7r