Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Red Hat OpenShift 3.7: RHSA-2017:3188-01 Moderate: Auth Bypass

red hat
Calendar Grey November 28, 2017
Scroller Redhat
The new version of Red Hat OpenShift Container Platform 3.7 includes enhancements that address security vulnerabilities with specific updates.
An update is now available for Red Hat OpenShift Container Platform 3.7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

For instructions on new installations, see the following documentation: anning.html

For instructions on how to properly upgrade existing clusters to OpenShift Container Platform 3.7, see the following documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/3.7/html/upgrading_clusters/index index.html

Summary

Red Hat OpenShift Container Platform is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
The OpenShift Container Platform 3.7 Release Notes, link located within the reference section, provides information about new features, bug fixes, and known issues.
This advisory contains the RPM packages for this release. An advisory for the container images for this release is available at: https://access.redhat.com/errata/RHEA-2017:3187.
Security Fix(es):
* An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices. (CVE-2017-12195)
Red Hat would like to thank Rich Megginson for reporting this issue.

References

https://access.redhat.com/security/cve/CVE-2017-12195 https://access.redhat.com/security/updates/classification/#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/3.7/html/release_notes/release-notes-ocp-3-7-release-notes

Package List

Red Hat OpenShift Container Platform 3.7:
Source: ansible-2.3.2.0-2.el7.src.rpm ansible-asb-modules-0.0.2-1.el7.src.rpm ansible-kubernetes-modules-0.3.1-6.el7.src.rpm ansible-service-broker-1.0.19-1.el7.src.rpm apb-1.0.4-1.el7.src.rpm apb-base-scripts-1.0.5-1.el7.src.rpm atomic-openshift-3.7.9-1.git.0.7c71a2d.el7.src.rpm atomic-openshift-descheduler-0.3.0-1.el7.src.rpm atomic-openshift-node-problem-detector-3.7.0-0.el7.src.rpm cockpit-155-1.el7.src.rpm containernetworking-plugins-0.5.2-4.el7.src.rpm cri-o-1.0.4-2.git4aceede.el7.src.rpm dumb-init-1.1.3-11.el7.src.rpm elastic-curator-3.5.0-2.el7.src.rpm elasticsearch-2.4.4-1.el7.src.rpm elasticsearch-cloud-kubernetes-2.4.4.01_redhat_1-1.el7.src.rpm fluentd-0.12.39-2.el7.src.rpm golang-github-openshift-oauth-proxy-2.1-1.git885c9f40.el7.src.rpm golang-github-openshift-prometheus-alert-buffer-0-1.gitceca8c1.el7.src.rpm golang-github-prometheus-alertmanager-0.9.1-2.git9f5f4b2.el7.src.rpm golang-github-prometheus-node_exporter-0.15.1-1.gitba5da2c.el7.src.rpm golang-github-prometheus-prometheus-2.0.0-1.git0a74f98.el7.src.rpm golang-github-prometheus-promu-0-1.git85ceabc.el7.src.rpm hawkular-openshift-agent-1.2.2-1.el7.src.rpm heapster-1.3.0-2.el7.src.rpm http-parser-2.7.1-4.el7.src.rpm image-inspector-2.1.2-1.el7.src.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:3188-01
Product: Red Hat OpenShift Enterprise
Issue date: 2017-11-28

Topic

An update is now available for Red Hat OpenShift Container Platform 3.7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat OpenShift Container Platform 3.7 - noarch, x86_64

Bugs Fixed

1270436 - Could not log in when client clock is > 5 minutes ahead of server clock

1292507 - pod terminal does not support 3rd level characters1316364 - Auto completion does not work normaly when command name is prefixed with path

1328913 - Long running reliability tests show network errors on nodes

1356478 - Openshift need update the output error message when try re-format the volume

1372059 - Dynamic provisioned volumes fail in AWS due to incorrect zone

1373418 - [atomic registry]Should give more detail info when creating Project and Image Stream with invalid name

1375134 - Navigation bar can not roll down when user zoom in till it cross over the screen boundary

1386917 - Deleting an image should allow references to the image to be deleted from imagestreamtags

1395564 - Unneeded spaces when copying content from terminal in web console

1401831 - docker-registry can't fetch requested blob from a remote registry when OpenShift is behind proxy

1410288 - DNSMasq and NetworkManager scripts cause boot issues with network resources

1413147 - Size of the emitted data exceeds buffer_chunk_limit

1415297 - Metrics does not install with cloud-provider and dynamic storage

1420543 - The --ports flag does not modify dc environment variables

1422049 - EmptyDir could lead to memory exhaustion

1427227 - Fix controller panic in creating pod event

1427992 - replicationcontrollers - not yet ready to handle request; Current resource version

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.