Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Red Hat OpenShift 2.2.9 RHSA-2016:0489-01 Important Remote Code Execution

red hat
Calendar Grey March 22, 2016
Scroller Redhat
Red Hat OpenShift Enterprise 2.2.9 resolves multiple vulnerabilities and introduces various improvements with significant security implications.
Red Hat OpenShift Enterprise release 2.2.9, which fixes several security issues, several bugs, and introduces feature enhancements, is now available

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

See the OpenShift Enterprise 2.2 Release Notes, which will be updated shortly for release 2.2.9, for important instructions on how to fully apply this asynchronous errata update:

ingle/2.2_Release_Notes/index.html#chap-Asynchronous_Errata_Updates

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at: https://access.redhat.com/articles/11258

Summary

OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
The following security issue is addressed with this release:
It was found that ActiveMQ did not safely handle user supplied data when deserializing objects. A remote attacker could use this flaw to execute arbitrary code with the permissions of the ActiveMQ application. (CVE-2015-5254)
An update for Jenkins Continuous Integration Server that addresses a large number of security issues including XSS, CSRF, information disclosure and code execution have been addressed as well. (CVE-2015-5317, CVE-2015-5318, CVE-2015-5319, CVE-2015-5320, CVE-2015-5321, CVE-2015-5322, CVE-2015-5323, CVE-2015-5324, CVE-2015-5325, CVE-2015-5326, CVE-2015-7537, CVE-2015-7538, CVE-2015-7539, CVE-2015-8103)
Space precludes documenting all of the bug fixes in this advisory. See the OpenShift Enterprise Technical Notes, which will be updated shortly for release 2.2.9, for details about these changes:
ingle/Technical_Notes/index.html
All OpenShift Enterprise 2 users are advised to upgrade to these updated packages.

References

https://access.redhat.com/security/cve/CVE-2015-5254 https://access.redhat.com/security/cve/CVE-2015-5317 https://access.redhat.com/security/cve/CVE-2015-5318 https://access.redhat.com/security/cve/CVE-2015-5319 https://access.redhat.com/security/cve/CVE-2015-5320 https://access.redhat.com/security/cve/CVE-2015-5321 https://access.redhat.com/security/cve/CVE-2015-5322 https://access.redhat.com/security/cve/CVE-2015-5323 https://access.redhat.com/security/cve/CVE-2015-5324 https://access.redhat.com/security/cve/CVE-2015-5325 https://access.redhat.com/security/cve/CVE-2015-5326 https://access.redhat.com/security/cve/CVE-2015-7537 https://access.redhat.com/security/cve/CVE-2015-7538 https://access.redhat.com/security/cve/CVE-2015-7539 https://access.redhat.com/security/cve/CVE-2015-8103 https://access.redhat.com/security/updates/classification#important

Package List

Red Hat OpenShift Enterprise Client 2.2:
Source: rhc-1.38.6.1-1.el6op.src.rpm
noarch: rhc-1.38.6.1-1.el6op.noarch.rpm
Red Hat OpenShift Enterprise Infrastructure 2.2:
Source: activemq-5.9.0-6.redhat.611454.el6op.src.rpm openshift-enterprise-upgrade-2.2.9-1.el6op.src.rpm openshift-origin-broker-util-1.37.5.3-1.el6op.src.rpm rubygem-openshift-origin-common-1.29.5.2-1.el6op.src.rpm rubygem-openshift-origin-console-1.35.5.1-1.el6op.src.rpm rubygem-openshift-origin-controller-1.38.5.1-1.el6op.src.rpm
noarch: openshift-enterprise-release-2.2.9-1.el6op.noarch.rpm openshift-enterprise-upgrade-broker-2.2.9-1.el6op.noarch.rpm openshift-enterprise-yum-validator-2.2.9-1.el6op.noarch.rpm openshift-origin-broker-util-1.37.5.3-1.el6op.noarch.rpm rubygem-openshift-origin-common-1.29.5.2-1.el6op.noarch.rpm rubygem-openshift-origin-console-1.35.5.1-1.el6op.noarch.rpm rubygem-openshift-origin-controller-1.38.5.1-1.el6op.noarch.rpm
x86_64: activemq-5.9.0-6.redhat.611454.el6op.x86_64.rpm activemq-client-5.9.0-6.redhat.611454.el6op.x86_64.rpm
Red Hat OpenShift Enterprise Node 2.2:
Source: activemq-5.9.0-6.redhat.611454.el6op.src.rpm jenkins-1.625.3-1.el6op.src.rpm openshift-enterprise-upgrade-2.2.9-1.el6op.src.rpm openshift-origin-cartridge-cron-1.25.2.1-1.el6op.src.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2016:0489-01
Product: Red Hat OpenShift Enterprise
Issue date: 2016-03-22

Topic

Red Hat OpenShift Enterprise release 2.2.9, which fixes several security issues, several bugs, and introduces feature enhancements, is now available.Red Hat Product Security has rated this update as having Importantsecurity impact. Common Vulnerability Scoring System (CVSS) basescores, which give detailed severity ratings, are available for eachvulnerability from the CVE links in the References section.

Relevant Releases Architectures

Red Hat OpenShift Enterprise Client 2.2 - noarch

Red Hat OpenShift Enterprise Infrastructure 2.2 - noarch, x86_64

Red Hat OpenShift Enterprise Node 2.2 - noarch, x86_64

Bugs Fixed

1111456 - jenkin app will be created as default small gear size when user create app with --enable-jenkins and non-default gear-size

1140816 - oo-admin-ctl-district missing documentation for listing districts

1160934 - "oo-admin-ctl-gears stopgear" failed to stop idled gear

1168480 - Should prompt correct information when execute oo-admin-ctl-user --addgearsize $invalid value

1169690 - Webconsole should show warning info when add cartridge as quota used up to QUOTA_WARNING_PERCENT

1265423 - .gitconfig is not configurable for application create

1265811 - oo-accept-node reports a quota failures when a loop device is used.

1279584 - Users have nil value for resulting in failed oo-admin-repair

1282359 - CVE-2015-5317 jenkins: Project name disclosure via fingerprints (SECURITY-153)

1282361 - CVE-2015-5318 jenkins: Public value used for CSRF protection salt (SECURITY-169)

1282362 - CVE-2015-5319 jenkins: XXE injection into job configurations via CLI (SECURITY-173)

1282363 - CVE-2015-5320 jenkins: Secret key not verified when connecting a slave (SECURITY-184)

1282364 - CVE-2015-5321 jenkins: Information disclosure via sidepanel (SECURITY-192)

1282365 - CVE-2015-5322 jenkins: Local file inclusion vulnerability (SECURITY-195)

1282366 - CVE-2015-5323 jenkins: API tokens of other users available to admins (SECURITY-200)

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.