RHSA-2020:2992: Moderate: OpenShift Container Platform 3.11 security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): cri-o: A flaw was found in cri-o that can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. (CVE-2019-14891) nodejs-minimist: Prototype pollution allows adding or modifying properties of Object.prototype using a constructor or proto payload. (CVE-2020-7598) kubernetes: Use of unbounded 'client' label in apiserverrequesttotal allows repeated, crafted HTTP requests to exhaust available memory and cause a crash. (CVE-2020-8552) kubernetes: A flaw was found in Kubernetes that allows attackers on adjacent networks to reach services exposed on localhost ports and gain privileges or access confidential information for any services listening on localhost ports that are not protected by authentication. (CVE-2020-8558) proglottis/gpgme: A use-after-free vulnerability was found in the Go GPGME wrapper library, github.com/proglottis/gpgme. (CVE-2020-8945) openshift/console: A flaw allowed text injection on error pages with a crafted URL. (CVE-2020-10715) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2992?
The severity of RHSA-2020:2992 is classified as moderate.
How do I fix RHSA-2020:2992?
To fix RHSA-2020:2992, upgrade to the specified remedial versions of affected packages listed in the advisory.
What packages are affected by RHSA-2020:2992?
Affected packages include atomic-openshift, cri-o, atomic-openshift-web-console, among others.
Is RHSA-2020:2992 specific to any version of Red Hat OpenShift?
Yes, RHSA-2020:2992 affects certain versions of Red Hat OpenShift Container Platform and its associated packages.
Where can I find more information about RHSA-2020:2992?
More information about RHSA-2020:2992 can typically be found in the Red Hat advisory.