Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Red Hat OpenShift: RHSA-2017:3389-01 Moderate: Authentication Bypass

red hat
Calendar Grey December 7, 2017
Scroller Redhat
Enhance your Red Hat OpenShift Container Platform to resolve significant security vulnerabilities and urgent software patches.
An update is now available for Red Hat OpenShift Container Platform 3.4, Red Hat OpenShift Container Platform 3.5, and Red Hat OpenShift Container Platform 3.6

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.
This advisory contains the RPM packages for this release. An advisory for the container images for this release is available at: https://access.redhat.com/errata/RHBA-2017:3390.
Space precludes documenting all of the bug fixes and enhancements in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:
ease_notes.html
ease_notes.html
ease_notes.html
All OpenShift Container Platform 3 users are advised to upgrade to these updated packages and images.
Security Fix(es):
* An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices. (CVE-2017-12195)
This issue was discovered by Rich Megginson (Red Hat).

References

https://access.redhat.com/security/cve/CVE-2017-12195 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat OpenShift Container Platform 3.4:
Source: atomic-openshift-3.4.1.44.38-1.git.0.d04b8d5.el7.src.rpm cockpit-155-1.el7.src.rpm openshift-elasticsearch-plugin-2.4.1.11__redhat_1-3.el7.src.rpm
noarch: atomic-openshift-docker-excluder-3.4.1.44.38-1.git.0.d04b8d5.el7.noarch.rpm atomic-openshift-excluder-3.4.1.44.38-1.git.0.d04b8d5.el7.noarch.rpm openshift-elasticsearch-plugin-2.4.1.11__redhat_1-3.el7.noarch.rpm
x86_64: atomic-openshift-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-clients-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-clients-redistributable-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-dockerregistry-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-master-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-node-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-pod-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-sdn-ovs-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm atomic-openshift-tests-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm cockpit-debuginfo-155-1.el7.x86_64.rpm cockpit-kubernetes-155-1.el7.x86_64.rpm tuned-profiles-atomic-openshift-node-3.4.1.44.38-1.git.0.d04b8d5.el7.x86_64.rpm
Red Hat OpenShift Container Platform 3.5:
Source:

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:3389-01
Product: Red Hat OpenShift Enterprise
Issue date: 2017-12-07

Topic

An update is now available for Red Hat OpenShift Container Platform 3.4,Red Hat OpenShift Container Platform 3.5, and Red Hat OpenShift ContainerPlatform 3.6.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat OpenShift Container Platform 3.4 - noarch, x86_64

Red Hat OpenShift Container Platform 3.5 - noarch, x86_64

Red Hat OpenShift Container Platform 3.6 - noarch, x86_64

Bugs Fixed

1399240 - pod age is shown invalid by oc client

1434942 - Symbolic link error for log file of every pod started when docker log driver is journald

1441089 - oc get/describe could not work when using 3.5 client to login 3.6 server

1457042 - Unable to pull through to registry.access.redhat.com

1458186 - Hawkular metrics rest api responding sporadically

1465532 - Heapster fails to push to Hawkular-Metrics sink starting around 4K pods in 3.6

1471251 - 3.4.1 White spaces in the cert prevents Origin Metrics from starting

1476026 - Service Catalog issues repeated Deprovision requests against the broker, despite a 410 response

1479955 - Container ose-sti-builder is marked as deprecated

1481550 - [3.5]'oadm diagnostics NetworkCheck' timeout due to image 'openshift/diagnostics-deployer' pull failed

1489023 - [3.4 Backport] Can not start atomic-openshift-node if the system does not have a default route

1489024 - [3.5 Backport] Can not start atomic-openshift-node if the system does not have a default route

1490719 - Enabled ops cluser,log in kibana-ops UI, there is no log entry under .all index, log entries only could be shown under .operations.* index

1492194 - [3.5] Node affinity alpha feature can cause scheduling failures across the cluster.

1493213 - Builds fail with "authentication required" after upgrade

1494239 - Fluentd unable to write to Elastic Search when LDAP distinguished names are used as usernames

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.