RHSA-2021:2500: Moderate: Red Hat OpenShift Enterprise security and bug fix update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): nodejs-handlebars: lookup helper fails to properly validate templates allowing for arbitrary JavaScript execution (CVE-2019-20920) nodejs-handlebars: an endless loop while processing specially-crafted templates leads to DoS (CVE-2019-20922) nodejs-handlebars: Remote code execution when compiling untrusted compile templates with strict:true option (CVE-2021-23369) nodejs-handlebars: Remote code execution when compiling untrusted compile templates with compat:true option (CVE-2021-23383) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Setting up Kibana and Elasticsearch replica to 0, Kibana pods are created and indexmanagement jobs (BZ#1942609)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2500?
The severity of RHSA-2021:2500 is classified as moderate.
How do I fix RHSA-2021:2500?
To fix RHSA-2021:2500, update the nodejs-handlebars package to the latest version provided by Red Hat.
What vulnerabilities are addressed in RHSA-2021:2500?
RHSA-2021:2500 addresses vulnerabilities related to the lookup helper in nodejs-handlebars that fails to properly validate templates.
What versions of Red Hat OpenShift Container Platform are affected by RHSA-2021:2500?
RHSA-2021:2500 affects specific versions of Red Hat OpenShift Container Platform that include the vulnerable nodejs-handlebars package.
Is there a workaround for RHSA-2021:2500?
There is no official workaround for RHSA-2021:2500; applying the update is recommended.