Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Before applying this update, ensure all previously released errata relevant
to your system have been applied. For details on how to apply this update,
see:
https://access.redhat.com/articles/11258
For instructions on new installations, see the following documentation:
For instructions on how to properly upgrade your OpenShift Enterprise
cluster from release 3.1 to release 3.2, see the following documentation:
For more information about OpenShift Enterprise, see the full
documentation:
https://docs.redhat.com/en
OpenShift Enterprise by Red Hat is the company's cloud computing Platform-
as-a-Service (PaaS) solution designed for on-premise or private cloud
deployments.
Security Fix(es):
* A flaw was found in the building of containers within OpenShift
Enterprise. An attacker could submit an image for building that executes
commands within the container as root, allowing them to potentially
escalate privileges. (CVE-2016-2160)
* It was found that OpenShift Enterprise would disclose log file contents
from reclaimed namespaces. An attacker could create a new namespace to
access log files present in a previously deleted namespace using the same
name. (CVE-2016-2149)
* An information disclosure flaw was discovered in haproxy as used by
OpenShift Enterprise; a cookie with the name
"OPENSHIFT_[namespace]_SERVERID" was set, which contained the internal IP
address of a pod. (CVE-2016-3711)
The CVE-2016-2149 issue was discovered by Wesley Hearn (Red Hat).
Additional Changes:
* Space precludes documenting all of the bug fixes and enhancements in this
advisory. For details on all new features, bug fixes, and known issues, see
the OpenShift Enterprise 3.2 Release Notes linked to in the References
section.
This update includes the following images:
openshift3/ose:v3.2.0.20-3
openshift3/ose-deployer:v3.2.0.20-3
openshift3/ose-docker-builder:v3.2.0.20-3
openshift3/ose-docker-registry:v3.2.0.20-3
openshift3/ose-f5-router:v3.2.0.20-3
openshift3/ose-haproxy-router:v3.2.0.20-3
openshift3/ose-keepalived-ipfailover:v3.2.0.20-3
openshift3/ose-pod:v3.2.0.20-3
openshift3/ose-recycler:v3.2.0.20-3
openshift3/ose-sti-builder:v3.2.0.20-3
openshift3/image-inspector:1.0.0-12
openshift3/jenkins-1-rhel7:1.642-31
openshift3/logging-auth-proxy:3.2.0-3
openshift3/logging-deployment:3.2.0-8
openshift3/logging-elasticsearch:3.2.0-7
openshift3/logging-fluentd:3.2.0-6
openshift3/logging-kibana:3.2.0-3
openshift3/metrics-cassandra:3.2.0-4
openshift3/metrics-deployer:3.2.0-5
openshift3/metrics-hawkular-metrics:3.2.0-6
openshift3/metrics-heapster:3.2.0-5
openshift3/mongodb-24-rhel7:2.4-27
openshift3/mysql-55-rhel7:5.5-25
openshift3/nodejs-010-rhel7:0.10-34
openshift3/node:v3.2.0.20-3
openshift3/openvswitch:v3.2.0.20-4
openshift3/perl-516-rhel7:5.16-37
openshift3/php-55-rhel7:5.5-34
openshift3/postgresql-92-rhel7:9.2-24
openshift3/python-33-rhel7:3.3-34
openshift3/ruby-20-rhel7:2.0-34
https://access.redhat.com/security/cve/CVE-2016-2149 https://access.redhat.com/security/cve/CVE-2016-2160 https://access.redhat.com/security/cve/CVE-2016-3711 https://access.redhat.com/security/updates/classification/#important
Red Hat OpenShift Enterprise 3.2:
Source:
ansible-1.9.4-1.el7aos.src.rpm
atomic-openshift-3.2.0.20-1.git.0.f44746c.el7.src.rpm
cockpit-0.93-3.el7.src.rpm
elastic-curator-3.5.0-2.el7.src.rpm
elasticsearch-1.5.2.redhat_1-11.el7.src.rpm
elasticsearch-cloud-kubernetes-1.2.1.redhat_1-1.el7.src.rpm
fluentd-0.12.20-1.el7.src.rpm
heapster-0.18.2-4.gitaf4752e.el7.src.rpm
http-parser-2.0-4.20121128gitcd01361.el7ost.src.rpm
image-inspector-1.0.0-1.el7aos.src.rpm
jenkins-1.642.2-1.el7.src.rpm
jenkins-plugin-credentials-1.24-2.el7.src.rpm
jenkins-plugin-durable-task-1.7-1.el7.src.rpm
jenkins-plugin-kubernetes-0.5-1.el7.src.rpm
jenkins-plugin-openshift-0.6.41-1.el7aos.src.rpm
jenkins-plugin-openshift-pipeline-1.0.9-1.el7.src.rpm
jenkins-plugin-promoted-builds-2.23-1.el7aos.src.rpm
jenkins-plugin-swarm-2.0-2.el7aos.src.rpm
kibana-4.1.2-2.el7aos.src.rpm
libuv-0.10.34-1.el7ost.src.rpm
lucene-4.10.4.redhat_1-5.el7.src.rpm
nodejs-0.10.36-3.el7ost.src.rpm
nodejs-abbrev-1.0.7-1.el7aos.src.rpm
nodejs-accepts-1.2.13-1.el7aos.src.rpm
nodejs-align-text-0.1.3-2.el7aos.src.rpm
nodejs-ansi-green-0.1.1-1.el7aos.src.rpm
nodejs-ansi-regex-2.0.0-1.el7aos.src.rpm
nodejs-ansi-styles-2.1.0-1.el7aos.src.rpm
nodejs-ansi-wrap-0.1.0-1.el7aos.src.rpm
nodejs-anymatch-1.3.0-1.el7aos.src.rpm
Read the Full Advisory
Red Hat OpenShift Enterprise 3.2 is now available.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat OpenShift Enterprise 3.2 - noarch, x86_64
1252520 - Openshift master spawns pods when out of disk space
1264500 - cannot pass comma-delimted values with oc parameters1273149 - openshift-master keeps getting killed due to memory usage after upgrade
1276038 - Can't access files from the downward API volume
1278719 - [userinterface_public_561]There is no "View Archive" button in build log page
1278974 - Unable to pull from another Secured Registry
1279344 - Inconsistent PV and PVC bound displayed
1282733 - [openshift3/postgresql-92-rhel7] Postgresql pod is CrashLoopBackOff if using persistent storage
1284700 - Heapster is using the deprecated externalID value to identify metrics
1285763 - A-MQ hawt.io console Browse message detail view header obscured
1291958 - Kubernetes service exposes wrong port for DNS
1293805 - Default SCC forbid recycler pod to be create, cause Persistent Volume failed to recycle
1293830 - Claim remains in 'Pending' status after it bounds dynamically created Persistent Volume
1293850 - Failed to delete dynamically provisioned PV when PVC is deleted
1296232 - EBS volume remains in 'detached' state
1297521 - Scaling up pod causes loop with Node is out of disk
1298942 - atomic-openshift-node crash
1299466 - heapster pod crashes repeatedly: invalid memory address or nil pointer dereference
1299756 - The existing pods loss network connection after remove lbr0 and restart node service
1300214 - Failed to build with openshift/golang-ex
Get the latest Linux and open source security news straight to your inbox.