Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Red Hat OpenShift 3.x RHSA-2017-0448 Important: Ansible Security Issues

red hat
Calendar Grey March 6, 2017
Scroller Redhat
Important patch released to fix vulnerabilities in ansible and openshift-ansible for OpenShift Environment. Update immediately.
An update for ansible and openshift-ansible is now available for Red Hat OpenShift Container Platform 3.2, Red Hat OpenShift Container Platform 3.3, and Red Hat OpenShift Container...

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To apply this update, run the following on all hosts where you intend to initiate Ansible-based installation or upgrade procedures:

# yum update atomic-openshift-utils

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at:

https://access.redhat.com/articles/11258

Summary

Red Hat OpenShift Container Platform is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
Ansible is a SSH-based configuration management, deployment, and task execution system. The openshift-ansible packages contain Ansible code and playbooks for installing and upgrading OpenShift Container Platform 3.
Security Fix(es):
* An input validation vulnerability was found in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges. (CVE-2016-9587)
Bug Fix(es):
Space precludes documenting all of the non-security bug fixes in this advisory. See the relevant OpenShift Container Platform Release Notes linked to in the References section, which will be updated shortly for this release.

References

https://access.redhat.com/security/cve/CVE-2016-9587 https://access.redhat.com/security/updates/classification/#important https://docs.redhat.com/en https://docs.redhat.com/en/documentation/openshift_container_platform/3.3/html/release_notes/release-notes-ocp-3-3-release-notes https://docs.redhat.com/en/documentation/openshift_container_platform/3.4/html/release_notes/release-notes-ocp-3-4-release-notes

Package List

Red Hat OpenShift Container Platform 3.2:
Source: ansible-2.2.1.0-2.el7.src.rpm openshift-ansible-3.2.53-1.git.0.2fefc17.el7.src.rpm
noarch: ansible-2.2.1.0-2.el7.noarch.rpm atomic-openshift-utils-3.2.53-1.git.0.2fefc17.el7.noarch.rpm openshift-ansible-3.2.53-1.git.0.2fefc17.el7.noarch.rpm openshift-ansible-docs-3.2.53-1.git.0.2fefc17.el7.noarch.rpm openshift-ansible-filter-plugins-3.2.53-1.git.0.2fefc17.el7.noarch.rpm openshift-ansible-lookup-plugins-3.2.53-1.git.0.2fefc17.el7.noarch.rpm openshift-ansible-playbooks-3.2.53-1.git.0.2fefc17.el7.noarch.rpm openshift-ansible-roles-3.2.53-1.git.0.2fefc17.el7.noarch.rpm
Red Hat OpenShift Container Platform 3.3:
Source: ansible-2.2.1.0-2.el7.src.rpm openshift-ansible-3.3.67-1.git.0.7c5da0c.el7.src.rpm
noarch: ansible-2.2.1.0-2.el7.noarch.rpm atomic-openshift-utils-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm openshift-ansible-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm openshift-ansible-callback-plugins-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm openshift-ansible-docs-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm openshift-ansible-filter-plugins-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm openshift-ansible-lookup-plugins-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm openshift-ansible-playbooks-3.3.67-1.git.0.7c5da0c.el7.noarch.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:0448-01
Product: Red Hat OpenShift Enterprise
Issue date: 2017-03-06

Topic

An update for ansible and openshift-ansible is now available for Red HatOpenShift Container Platform 3.2, Red Hat OpenShift Container Platform 3.3,and Red Hat OpenShift Container Platform 3.4.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat OpenShift Container Platform 3.2 - noarch

Red Hat OpenShift Container Platform 3.3 - noarch

Red Hat OpenShift Container Platform 3.4 - noarch

Bugs Fixed

1379189 - [3.2] ansible sometimes gets UNREACHABLE error after iptables restarted

1388016 - [3.3] The insecure-registry address was removed during upgrade

1389263 - [3.4] the summary of json report should include total/ok number after certificate expiry check

1393000 - [3.3] Ansible upgrade from 3.2 to 3.3 fails

1404378 - CVE-2016-9587 Ansible: Compromised remote hosts can lead to running commands on the Ansible controller

1414276 - [3.3] Installer is failing when `ansible_user` is set to Windows Login which requires domuser format

1415067 - [3.2]Installer should persist net.ipv4.ip_forward

1416926 - [3.3] ansible sometimes gets UNREACHABLE error after iptables restarted

1416927 - [3.4] ansible sometimes gets UNREACHABLE error after iptables restarted

1417680 - [3.2] Backport openshift_certificate_expiry role

1417681 - [3.4] Backport openshift_certificate_expiry role

1417682 - [3.3] Backport openshift_certificate_expiry role

1419493 - [3.4] Installer pulls in 3.3 registry-console image

1419533 - [3.2]Installation on node failed when creating node config

1419654 - [3.4] Containerized advanced installation fails due to missing CA certificate /etc/origin/master/ca.crt

1420393 - [3.4] conntrack executable not found on $PATH during cluster horizontal run

1420395 - [3.3] conntrack executable not found on $PATH during cluster horizontal run

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.