Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:2369-1 Moderate: Cri-O TLS Connection Enforcement Fix

suse
Calendar Grey September 12, 2019
Dist Suse Esm H88
Red Hat Security Update for openshift-origin resolves a considerable concern. Advisory ID: RHEA-2021:1935-1. Update to secure communication protocols applied.
An update that fixes one vulnerability is now available

Summary

This update for cri-o fixes the following issues: Security issues fixed: - CVE-2019-10214: Fixed missing enforcement of TLS connections. (bsc#1144065) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform 4.0 (x86_64): cri-o-1.15.0-3.3.2 cri-o-kubeadm-criconfig-1.15.0-3.3.2

References

#1144065

Cross- CVE-2019-10214

Affected Products:

SUSE CaaS Platform 4.0

https://www.suse.com/security/cve/CVE-2019-10214.html

https://bugzilla.suse.com/1144065

Announcement ID: SUSE-SU-2019:2369-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here