- Issued:
- 2023-06-21
- Updated:
- 2023-06-21
RHSA-2023:3742 - Important: Red Hat OpenShift Data Foundation 4.13.0 security and bug fix update
Synopsis
Important: Red Hat OpenShift Data Foundation 4.13.0 security and bug fix update
Type/Severity
Security Advisory Important
Topic
Updated images that include numerous enhancements, security, and bug fixes are now available in Red Hat Container Registry for Red Hat OpenShift Data Foundation 4.13.0 on Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multicloud data management service with an S3 compatible API.
Security Fix(es):
-
goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238)
-
decode-uri-component: improper input validation resulting in DoS (CVE-2022-38900)
-
vault: Hashicorp Vault AWS IAM Integration Authentication Bypass (CVE-2020-16250)
-
vault: GCP Auth Method Allows Authentication Bypass (CVE-2020-16251)
-
nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)
-
go-yaml: Denial of Service in go-yaml (CVE-2021-4235)
-
vault: incorrect policy enforcement (CVE-2021-43998)
-
nodejs: Improper handling of URI Subject Alternative Names (CVE-2021-44531)
-
nodejs: Certificate Verification Bypass via String Injection (CVE-2021-44532)
-
nodejs: Incorrect handling of certificate subject and issuer fields (CVE-2021-44533)
-
golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879)
-
golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)
-
nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
-
jsonwebtoken: Insecure default algorithm in jwt.verify() could lead to signature validation bypass (CVE-2022-23540)
-
jsonwebtoken: Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC (CVE-2022-23541)
-
golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664)
-
golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
-
golang: net/url: JoinPath does not strip relative path components in all circumstances (CVE-2022-32190)
-
consul: Consul Template May Expose Vault Secrets When Processing Invalid Input (CVE-2022-38149)
-
vault: insufficient certificate revocation list checking (CVE-2022-41316)
-
golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)
-
golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)
-
net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
-
golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
-
golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
-
json5: Prototype Pollution in JSON5 via Parse Method (CVE-2022-46175)
-
vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File (CVE-2023-0620)
-
hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata (CVE-2023-0665)
-
Hashicorp/vault: Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation (CVE-2023-24999)
-
hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations (CVE-2023-25000)
-
validator: Inefficient Regular Expression Complexity in Validator.js (CVE-2021-3765)
-
nodejs: Prototype pollution via console.table properties (CVE-2022-21824)
-
golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Solution
These updated images include numerous enhancements and bug fixes. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat OpenShift Data Foundation Release Notes for information on the most significant of these changes:
All Red Hat OpenShift Data Foundation users are advised to upgrade to these updated images that provide numerous bug fixes and enhancements.
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat OpenShift Data Foundation | 4 | x86_64 |
| Red Hat OpenShift Data Foundation for RHEL 9 ARM | 4 | aarch64 |
| Red Hat OpenShift Data Foundation for IBM Z and LinuxONE | 4 | s390x |
| Red Hat OpenShift Data Foundation for IBM Power, little endian | 4 | ppc64le |
Fixes
- This content is not included.BZ - 1786696
- This content is not included.BZ - 1855339
- This content is not included.BZ - 1943137
- This content is not included.BZ - 1944687
- This content is not included.BZ - 1989088
- This content is not included.BZ - 2005040
- This content is not included.BZ - 2005830
- This content is not included.BZ - 2007557
- This content is not included.BZ - 2028193
- This content is not included.BZ - 2040839
- This content is not included.BZ - 2040846
- This content is not included.BZ - 2040856
- This content is not included.BZ - 2040862
- This content is not included.BZ - 2042914
- This content is not included.BZ - 2052252
- This content is not included.BZ - 2101497
- This content is not included.BZ - 2101916
- This content is not included.BZ - 2102304
- This content is not included.BZ - 2104148
- This content is not included.BZ - 2107388
- This content is not included.BZ - 2113814
- This content is not included.BZ - 2115020
- This content is not included.BZ - 2115616
- This content is not included.BZ - 2119551
- This content is not included.BZ - 2120098
- This content is not included.BZ - 2120944
- This content is not included.BZ - 2124668
- This content is not included.BZ - 2124669
- This content is not included.BZ - 2126299
- This content is not included.BZ - 2132867
- This content is not included.BZ - 2132868
- This content is not included.BZ - 2132872
- This content is not included.BZ - 2134609
- This content is not included.BZ - 2135339
- This content is not included.BZ - 2139037
- This content is not included.BZ - 2141095
- This content is not included.BZ - 2142651
- This content is not included.BZ - 2142894
- This content is not included.BZ - 2142941
- This content is not included.BZ - 2143944
- This content is not included.BZ - 2144256
- This content is not included.BZ - 2151903
- This content is not included.BZ - 2152143
- This content is not included.BZ - 2154250
- This content is not included.BZ - 2155507
- This content is not included.BZ - 2155743
- This content is not included.BZ - 2156067
- This content is not included.BZ - 2156069
- This content is not included.BZ - 2156263
- This content is not included.BZ - 2156519
- This content is not included.BZ - 2156727
- This content is not included.BZ - 2156729
- This content is not included.BZ - 2157876
- This content is not included.BZ - 2158922
- This content is not included.BZ - 2159676
- This content is not included.BZ - 2161274
- This content is not included.BZ - 2161879
- This content is not included.BZ - 2161937
- This content is not included.BZ - 2162257
- This content is not included.BZ - 2164617
- This content is not included.BZ - 2165495
- This content is not included.BZ - 2165504
- This content is not included.BZ - 2165929
- This content is not included.BZ - 2165938
- This content is not included.BZ - 2165984
- This content is not included.BZ - 2166222
- This content is not included.BZ - 2166234
- This content is not included.BZ - 2166869
- This content is not included.BZ - 2167299
- This content is not included.BZ - 2167308
- This content is not included.BZ - 2167337
- This content is not included.BZ - 2167340
- This content is not included.BZ - 2167946
- This content is not included.BZ - 2168113
- This content is not included.BZ - 2168635
- This content is not included.BZ - 2168840
- This content is not included.BZ - 2168849
- This content is not included.BZ - 2169375
- This content is not included.BZ - 2169378
- This content is not included.BZ - 2169779
- This content is not included.BZ - 2170644
- This content is not included.BZ - 2170673
- This content is not included.BZ - 2172089
- This content is not included.BZ - 2172365
- This content is not included.BZ - 2172521
- This content is not included.BZ - 2173161
- This content is not included.BZ - 2173528
- This content is not included.BZ - 2173534
- This content is not included.BZ - 2173926
- This content is not included.BZ - 2175612
- This content is not included.BZ - 2175685
- This content is not included.BZ - 2175714
- This content is not included.BZ - 2175867
- This content is not included.BZ - 2176080
- This content is not included.BZ - 2176456
- This content is not included.BZ - 2176739
- This content is not included.BZ - 2176776
- This content is not included.BZ - 2176798
- This content is not included.BZ - 2176809
- This content is not included.BZ - 2177134
- This content is not included.BZ - 2177221
- This content is not included.BZ - 2177325
- This content is not included.BZ - 2177695
- This content is not included.BZ - 2177844
- This content is not included.BZ - 2178033
- This content is not included.BZ - 2178358
- This content is not included.BZ - 2178488
- This content is not included.BZ - 2178492
- This content is not included.BZ - 2178588
- This content is not included.BZ - 2178619
- This content is not included.BZ - 2178682
- This content is not included.BZ - 2179133
- This content is not included.BZ - 2179337
- This content is not included.BZ - 2179403
- This content is not included.BZ - 2179846
- This content is not included.BZ - 2179860
- This content is not included.BZ - 2179976
- This content is not included.BZ - 2179981
- This content is not included.BZ - 2179997
- This content is not included.BZ - 2180211
- This content is not included.BZ - 2180397
- This content is not included.BZ - 2180440
- This content is not included.BZ - 2180921
- This content is not included.BZ - 2181112
- This content is not included.BZ - 2181133
- This content is not included.BZ - 2181446
- This content is not included.BZ - 2181535
- This content is not included.BZ - 2181551
- This content is not included.BZ - 2181832
- This content is not included.BZ - 2181949
- This content is not included.BZ - 2182041
- This content is not included.BZ - 2182296
- This content is not included.BZ - 2182375
- This content is not included.BZ - 2182644
- This content is not included.BZ - 2182664
- This content is not included.BZ - 2182703
- This content is not included.BZ - 2182972
- This content is not included.BZ - 2182981
- This content is not included.BZ - 2183155
- This content is not included.BZ - 2183196
- This content is not included.BZ - 2183266
- This content is not included.BZ - 2183457
- This content is not included.BZ - 2183478
- This content is not included.BZ - 2183520
- This content is not included.BZ - 2184068
- This content is not included.BZ - 2184605
- This content is not included.BZ - 2184663
- This content is not included.BZ - 2184769
- This content is not included.BZ - 2184773
- This content is not included.BZ - 2184892
- This content is not included.BZ - 2184984
- This content is not included.BZ - 2185164
- This content is not included.BZ - 2185188
- This content is not included.BZ - 2185757
- This content is not included.BZ - 2185871
- This content is not included.BZ - 2186171
- This content is not included.BZ - 2186225
- This content is not included.BZ - 2186475
- This content is not included.BZ - 2186752
- This content is not included.BZ - 2187251
- This content is not included.BZ - 2187296
- This content is not included.BZ - 2187736
- This content is not included.BZ - 2187952
- This content is not included.BZ - 2187969
- This content is not included.BZ - 2187986
- This content is not included.BZ - 2188053
- This content is not included.BZ - 2188238
- This content is not included.BZ - 2188303
- This content is not included.BZ - 2188427
- This content is not included.BZ - 2188666
- This content is not included.BZ - 2189483
- This content is not included.BZ - 2189929
- This content is not included.BZ - 2189982
- This content is not included.BZ - 2189984
- This content is not included.BZ - 2190129
- This content is not included.BZ - 2190241
- This content is not included.BZ - 2192088
- This content is not included.BZ - 2192670
- This content is not included.BZ - 2192824
- This content is not included.BZ - 2192875
- This content is not included.BZ - 2193114
- This content is not included.BZ - 2193220
- This content is not included.BZ - 2196176
- This content is not included.BZ - 2196236
- This content is not included.BZ - 2196298
- This content is not included.BZ - 2203795
- This content is not included.BZ - 2208029
- This content is not included.BZ - 2208079
- This content is not included.BZ - 2208269
- This content is not included.BZ - 2208558
- This content is not included.BZ - 2208962
- This content is not included.BZ - 2209364
- This content is not included.BZ - 2209643
- This content is not included.BZ - 2209695
- This content is not included.BZ - 2210964
- This content is not included.BZ - 2211334
- This content is not included.BZ - 2211343
- This content is not included.BZ - 2211704
CVEs
- CVE-2015-20107
- CVE-2018-25032
- CVE-2020-10735
- CVE-2020-16250
- CVE-2020-16251
- CVE-2020-17049
- CVE-2021-3765
- CVE-2021-3807
- CVE-2021-4231
- CVE-2021-4235
- CVE-2021-4238
- CVE-2021-28861
- CVE-2021-43519
- CVE-2021-43998
- CVE-2021-44531
- CVE-2021-44532
- CVE-2021-44533
- CVE-2021-44964
- CVE-2021-46828
- CVE-2021-46848
- CVE-2022-0670
- CVE-2022-1271
- CVE-2022-1304
- CVE-2022-1348
- CVE-2022-1586
- CVE-2022-1587
- CVE-2022-2309
- CVE-2022-2509
- CVE-2022-2795
- CVE-2022-2879
- CVE-2022-2880
- CVE-2022-3094
- CVE-2022-3358
- CVE-2022-3515
- CVE-2022-3517
- CVE-2022-3715
- CVE-2022-3736
- CVE-2022-3821
- CVE-2022-3924
- CVE-2022-4415
- CVE-2022-21824
- CVE-2022-23540
- CVE-2022-23541
- CVE-2022-24903
- CVE-2022-26280
- CVE-2022-27664
- CVE-2022-28805
- CVE-2022-29154
- CVE-2022-30635
- CVE-2022-31129
- CVE-2022-32189
- CVE-2022-32190
- CVE-2022-33099
- CVE-2022-34903
- CVE-2022-35737
- CVE-2022-36227
- CVE-2022-37434
- CVE-2022-38149
- CVE-2022-38900
- CVE-2022-40023
- CVE-2022-40303
- CVE-2022-40304
- CVE-2022-40897
- CVE-2022-41316
- CVE-2022-41715
- CVE-2022-41717
- CVE-2022-41723
- CVE-2022-41724
- CVE-2022-41725
- CVE-2022-42010
- CVE-2022-42011
- CVE-2022-42012
- CVE-2022-42898
- CVE-2022-42919
- CVE-2022-43680
- CVE-2022-45061
- CVE-2022-45873
- CVE-2022-46175
- CVE-2022-47024
- CVE-2022-47629
- CVE-2022-48303
- CVE-2022-48337
- CVE-2022-48338
- CVE-2022-48339
- CVE-2023-0361
- CVE-2023-0620
- CVE-2023-0665
- CVE-2023-2491
- CVE-2023-22809
- CVE-2023-24329
- CVE-2023-24999
- CVE-2023-25000
- CVE-2023-25136
References
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-us/red_hat_openshift_data_foundation/4.13/html/4.13_release_notes/index
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.