RHSA-2021:2431: Important: OpenShift Container Platform 4.5.41 security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.This advisory contains the RPM packages for Red Hat OpenShift ContainerPlatform 4.5.41. See the following advisory for the container images forthis release:https://access.redhat.com/errata/RHSA-2021:2430 Security Fix(es): jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. (CVE-2021-21642) jetty: local temporary directory hijacking vulnerability (CVE-2020-27216) jetty: buffer not correctly recycled in Gzip Request inflation (CVE-2020-27218) jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS (CVE-2020-27223) jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. (CVE-2021-21643) jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. (CVE-2021-21644) jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints. (CVE-2021-21645) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Placeholder bug for OCP 4.5.41 rpm release (BZ#1972114)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2431?
The severity of RHSA-2021:2431 is classified as moderate.
How do I fix RHSA-2021:2431?
To fix RHSA-2021:2431, update the affected packages to the latest versions specified in the advisory.
What systems are affected by RHSA-2021:2431?
RHSA-2021:2431 affects Red Hat OpenShift Container Platform version 4.5.0 and its associated components.
Are there any workarounds for RHSA-2021:2431?
There are no officially recommended workarounds for RHSA-2021:2431 apart from applying the necessary updates.
When was RHSA-2021:2431 released?
RHSA-2021:2431 was released on June 1, 2021.