Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Red Hat OpenShift 3.2 RHSA-2016:1064-01 Important: Security Fixes Ahead

red hat
Calendar Grey May 12, 2016
Scroller Redhat
Red Hat OpenShift Container Platform 3.2 upgrade offers critical security enhancements addressing multiple vulnerabilities. Discover further details.
Red Hat OpenShift Enterprise 3.2 is now available

Solution

Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, see:

https://access.redhat.com/articles/11258

For instructions on new installations, see the following documentation:


For instructions on how to properly upgrade your OpenShift Enterprise cluster from release 3.1 to release 3.2, see the following documentation:


For more information about OpenShift Enterprise, see the full documentation:

https://docs.redhat.com/en

Summary

OpenShift Enterprise by Red Hat is the company's cloud computing Platform- as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
Security Fix(es):
* A flaw was found in the building of containers within OpenShift Enterprise. An attacker could submit an image for building that executes commands within the container as root, allowing them to potentially escalate privileges. (CVE-2016-2160)
* It was found that OpenShift Enterprise would disclose log file contents from reclaimed namespaces. An attacker could create a new namespace to access log files present in a previously deleted namespace using the same name. (CVE-2016-2149)
* An information disclosure flaw was discovered in haproxy as used by OpenShift Enterprise; a cookie with the name "OPENSHIFT_[namespace]_SERVERID" was set, which contained the internal IP address of a pod. (CVE-2016-3711)
The CVE-2016-2149 issue was discovered by Wesley Hearn (Red Hat).
Additional Changes:
* Space precludes documenting all of the bug fixes and enhancements in this advisory. For details on all new features, bug fixes, and known issues, see the OpenShift Enterprise 3.2 Release Notes linked to in the References section.
This update includes the following images:
openshift3/ose:v3.2.0.20-3 openshift3/ose-deployer:v3.2.0.20-3 openshift3/ose-docker-builder:v3.2.0.20-3 openshift3/ose-docker-registry:v3.2.0.20-3 openshift3/ose-f5-router:v3.2.0.20-3 openshift3/ose-haproxy-router:v3.2.0.20-3 openshift3/ose-keepalived-ipfailover:v3.2.0.20-3 openshift3/ose-pod:v3.2.0.20-3 openshift3/ose-recycler:v3.2.0.20-3 openshift3/ose-sti-builder:v3.2.0.20-3 openshift3/image-inspector:1.0.0-12 openshift3/jenkins-1-rhel7:1.642-31 openshift3/logging-auth-proxy:3.2.0-3 openshift3/logging-deployment:3.2.0-8 openshift3/logging-elasticsearch:3.2.0-7 openshift3/logging-fluentd:3.2.0-6 openshift3/logging-kibana:3.2.0-3 openshift3/metrics-cassandra:3.2.0-4 openshift3/metrics-deployer:3.2.0-5 openshift3/metrics-hawkular-metrics:3.2.0-6 openshift3/metrics-heapster:3.2.0-5 openshift3/mongodb-24-rhel7:2.4-27 openshift3/mysql-55-rhel7:5.5-25 openshift3/nodejs-010-rhel7:0.10-34 openshift3/node:v3.2.0.20-3 openshift3/openvswitch:v3.2.0.20-4 openshift3/perl-516-rhel7:5.16-37 openshift3/php-55-rhel7:5.5-34 openshift3/postgresql-92-rhel7:9.2-24 openshift3/python-33-rhel7:3.3-34 openshift3/ruby-20-rhel7:2.0-34

References

https://access.redhat.com/security/cve/CVE-2016-2149 https://access.redhat.com/security/cve/CVE-2016-2160 https://access.redhat.com/security/cve/CVE-2016-3711 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat OpenShift Enterprise 3.2:
Source: ansible-1.9.4-1.el7aos.src.rpm atomic-openshift-3.2.0.20-1.git.0.f44746c.el7.src.rpm cockpit-0.93-3.el7.src.rpm elastic-curator-3.5.0-2.el7.src.rpm elasticsearch-1.5.2.redhat_1-11.el7.src.rpm elasticsearch-cloud-kubernetes-1.2.1.redhat_1-1.el7.src.rpm fluentd-0.12.20-1.el7.src.rpm heapster-0.18.2-4.gitaf4752e.el7.src.rpm http-parser-2.0-4.20121128gitcd01361.el7ost.src.rpm image-inspector-1.0.0-1.el7aos.src.rpm jenkins-1.642.2-1.el7.src.rpm jenkins-plugin-credentials-1.24-2.el7.src.rpm jenkins-plugin-durable-task-1.7-1.el7.src.rpm jenkins-plugin-kubernetes-0.5-1.el7.src.rpm jenkins-plugin-openshift-0.6.41-1.el7aos.src.rpm jenkins-plugin-openshift-pipeline-1.0.9-1.el7.src.rpm jenkins-plugin-promoted-builds-2.23-1.el7aos.src.rpm jenkins-plugin-swarm-2.0-2.el7aos.src.rpm kibana-4.1.2-2.el7aos.src.rpm libuv-0.10.34-1.el7ost.src.rpm lucene-4.10.4.redhat_1-5.el7.src.rpm nodejs-0.10.36-3.el7ost.src.rpm nodejs-abbrev-1.0.7-1.el7aos.src.rpm nodejs-accepts-1.2.13-1.el7aos.src.rpm nodejs-align-text-0.1.3-2.el7aos.src.rpm nodejs-ansi-green-0.1.1-1.el7aos.src.rpm nodejs-ansi-regex-2.0.0-1.el7aos.src.rpm nodejs-ansi-styles-2.1.0-1.el7aos.src.rpm nodejs-ansi-wrap-0.1.0-1.el7aos.src.rpm nodejs-anymatch-1.3.0-1.el7aos.src.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2016:1064-01
Product: Red Hat OpenShift Enterprise
Advisory URL: Issue date: 2016-05-12

Topic

Red Hat OpenShift Enterprise 3.2 is now available.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat OpenShift Enterprise 3.2 - noarch, x86_64

Bugs Fixed

1252520 - Openshift master spawns pods when out of disk space

1264500 - cannot pass comma-delimted values with oc parameters1273149 - openshift-master keeps getting killed due to memory usage after upgrade

1276038 - Can't access files from the downward API volume

1278719 - [userinterface_public_561]There is no "View Archive" button in build log page

1278974 - Unable to pull from another Secured Registry

1279344 - Inconsistent PV and PVC bound displayed

1282733 - [openshift3/postgresql-92-rhel7] Postgresql pod is CrashLoopBackOff if using persistent storage

1284700 - Heapster is using the deprecated externalID value to identify metrics

1285763 - A-MQ hawt.io console Browse message detail view header obscured

1291958 - Kubernetes service exposes wrong port for DNS

1293805 - Default SCC forbid recycler pod to be create, cause Persistent Volume failed to recycle

1293830 - Claim remains in 'Pending' status after it bounds dynamically created Persistent Volume

1293850 - Failed to delete dynamically provisioned PV when PVC is deleted

1296232 - EBS volume remains in 'detached' state

1297521 - Scaling up pod causes loop with Node is out of disk

1298942 - atomic-openshift-node crash

1299466 - heapster pod crashes repeatedly: invalid memory address or nil pointer dereference

1299756 - The existing pods loss network connection after remove lbr0 and restart node service

1300214 - Failed to build with openshift/golang-ex

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.