Security Lab

Множественные уязвимости в OpenShift Container Platform 4.7

Дата публикации:19.01.2022
Всего просмотров:361
Опасность:
Средняя
Наличие исправления: Да
Количество уязвимостей:2
CVSSv3.1 рейтинг: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
7.2 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:P/RL:O/RC:C]
CVE ID: CVE-2021-39241
CVE-2021-40346
Вектор эксплуатации: Удаленная
Воздействие: Обход ограничений безопасности
CWE ID: Нет данных
Наличие эксплоита: Нет данных
Уязвимые продукты: Red Hat OpenShift Container Platform
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
haproxy (Red Hat package)
cri-o (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
Уязвимые версии: Red Hat OpenShift Container Platform версии 4.7.41, 4.7.40, 4.7.39, 4.7.38, 4.7.37, 4.7.36, 4.7.34, 4.7.33, 4.7.32, 4.7.31, 4.7.30, 4.7.29, 4.7.28, 4.7.24, 4.7.23, 4.7.22, 4.7.21, 4.7.19, 4.7.18, 4.7.16, 4.7.13, 4.7.12, 4.7.11, 4.7.9, 4.7.8, 4.7.7, 4.7.6, 4.7.5, 4.7.4, 4.7.3, 4.7.2, 4.7.1, 4.7.0
openshift-ansible (Red Hat package) версии 4.7.0-202201082234.p0.g4a5273a.assembly.stream.el7, 4.7.0-202107292046.p0.git.e1b19c2.assembly.stream.el7, 4.7.0-202107070256.p0.git.e1b19c2.assembly.stream.el7, 4.7.0-202105111743.p0.git.e1b19c2.el7, 4.7.0-202104250659.p0.git.e1b19c2.el7, 4.7.0-202103181433.p0.git.0.729df27.el7
openshift-kuryr (Red Hat package) версии 4.7.0-202201082234.p0.g72de60e.assembly.stream.el8, 4.7.0-202107291238.p0.git.c7654fb.assembly.stream.el8, 4.7.0-202107070256.p0.git.c7654fb.assembly.stream.el8, 4.7.0-202106232224.p0.git.c7654fb.el8, 4.7.0-202105140104.p0.git.8b61936.el8, 4.7.0-202105111743.p0.git.36c2cdd.el8, 4.7.0-202104250659.p0.git.d49acc4.el8, 4.7.0-202103171728.p0.git.2502.8383c08.el8
openshift-clients (Red Hat package) версии 4.7.0-202201082234.p0.g25914b8.assembly.stream.el7, 4.7.0-202201082234.p0.g25914b8.assembly.stream.el8, 4.7.0-202107292242.p0.git.8b4b094.assembly.stream.el7, 4.7.0-202107292242.p0.git.8b4b094.assembly.stream.el8, 4.7.0-202107070256.p0.git.8b4b094.assembly.stream.el7, 4.7.0-202107070256.p0.git.8b4b094.assembly.stream.el8, 4.7.0-202106252127.p0.git.8b4b094.el7, 4.7.0-202106252127.p0.git.8b4b094.el8, 4.7.0-202105111743.p0.git.95881af.el7, 4.7.0-202105111743.p0.git.95881af.el8, 4.7.0-202104250659.p0.git.95881af.el7, 4.7.0-202104250659.p0.git.95881af.el8, 4.7.0-202103191426.p0.git.3953.f3a7513.el7, 4.7.0-202103191426.p0.git.3953.f3a7513.el8
openshift (Red Hat package) версии 4.7.0-202201082234.p0.ge880017.assembly.stream.el7, 4.7.0-202201082234.p0.ge880017.assembly.stream.el8, 4.7.0-202111192046.p0.gaa025a0.assembly.stream.el7, 4.7.0-202111192046.p0.gaa025a0.assembly.stream.el8, 4.7.0-202109172126.p0.git.bbbc079.assembly.stream.el7, 4.7.0-202109172126.p0.git.bbbc079.assembly.stream.el8, 4.7.0-202107292242.p0.git.558d959.assembly.stream.el7, 4.7.0-202107292242.p0.git.558d959.assembly.stream.el8, 4.7.0-202107132131.p0.git.558d959.assembly.stream.el7, 4.7.0-202107132131.p0.git.558d959.assembly.stream.el8, 4.7.0-202105160013.p0.git.df9c838.el7, 4.7.0-202105160013.p0.git.df9c838.el8, 4.7.0-202105111743.p0.git.75370d3.el7, 4.7.0-202105111743.p0.git.75370d3.el8, 4.7.0-202104250659.p0.git.7d0a2b2.el7, 4.7.0-202104250659.p0.git.7d0a2b2.el8, 4.7.0-202104090228.p0.git.97111.77863f8.el7, 4.7.0-202104090228.p0.git.97111.77863f8.el8, 4.7.0-202103181538.p0.git.97109.7576cdc.el7, 4.7.0-202103181538.p0.git.97109.7576cdc.el8
haproxy (Red Hat package) версии 2.0.19-2.el7, 2.0.19-2.el8, 2.0.16-2.el7, 2.0.16-4.el8, 2.0.13-3.el7, 2.0.13-3.el8
cri-o (Red Hat package) версии 1.20.6-5.rhaos4.7.git8594c20.el7, 1.20.6-5.rhaos4.7.git8594c20.el8, 1.20.6-3.rhaos4.7.git4603183.el7, 1.20.6-3.rhaos4.7.git4603183.el8
atomic-openshift-service-idler (Red Hat package) версии 4.7.0-202201082234.p0.g39cfc66.assembly.stream.el8, 4.7.0-202107291238.p0.git.39cfc66.assembly.stream.el8, 4.7.0-202107070256.p0.git.39cfc66.assembly.stream.el8, 4.7.0-202105111743.p0.git.39cfc66.el8, 4.7.0-202104260636.p0.git.330c6ef.el8
Описание:

Множественные уязвимости в OpenShift Container Platform 4.7

Решение: Установите исправление с сайта производителя.
Ссылки: https://access.redhat.com/errata/RHSA-2022:0114