RHEL 7 : OpenShift Container Platform 3.11.394 (RHSA-2021:0637)

high Nessus Plugin ID 147013

Synopsis

The remote Red Hat host is missing one or more security updates for OpenShift Container Platform 3.11.394.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2021:0637 advisory.

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

Security Fix(es):

* jenkins-2-plugins/subversion: XML parser is not preventing XML external entity (XXE) attacks (CVE-2020-2304)

* jenkins-2-plugins/mercurial: XML parser is not preventing XML external entity (XXE) attacks (CVE-2020-2305)

* ant: Insecure temporary file vulnerability (CVE-2020-1945)

* jenkins-2-plugins/mercurial: Missing permission check in an HTTP endpoint could result in information disclosure (CVE-2020-2306)

* jenkins-2-plugins/kubernetes: Jenkins controller environment variables are accessible in Kubernetes plug-in (CVE-2020-2307)

* jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes Plugin allows listing pod templates (CVE-2020-2308)

* jenkins-2-plugins/kubernetes: Missing permission check in Kubernetes plug-in allows enumerating credentials IDs (CVE-2020-2309)

* ant: Insecure temporary file (CVE-2020-11979)

* python-rsa: Bleichenbacher timing oracle attack against RSA decryption (CVE-2020-25658)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 3.11.394. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHBA-2021:0638

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html

This update fixes the following bugs among others:

* Previously, the restart-cluster playbook did not evaluate the defined cluster size for ops clusters.
This was causing come clusters to never complete their restart. This bug fix passes the logging ops cluster size, allowing restarts of ops clusters to complete successfully. (BZ#1879407)

* Previously, the `openshift_named_certificates` role checked the contents of the `ca-bundle.crt` file during cluster installation. This caused the check to fail during initial installation because the `ca- bundle.crt` file is not yet created in that scenario. This bug fix allows the cluster to skip checking the `ca-bundle.crt` file if it does not exist, resulting in initial installations succeeding. (BZ#1920567)

* Previously, if the `openshift_release` attribute was not set in the Ansible inventory file, the nodes of the cluster would fail during an upgrade. This was caused by the `cluster_facts.yml` file being gathered before the `openshift_release` attribute was defined by the upgrade playbook. Now the `cluster_facts.yml` file is gathered after the `openshift_version` role runs and the `openshift_release` attribute is set, allowing for successful node upgrades. (BZ#1921353)

All OpenShift Container Platform 3.11 users are advised to upgrade to these updated packages and images.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL OpenShift Container Platform 3.11.394 package based on the guidance in RHSA-2021:0637.

See Also

http://www.nessus.org/u?9d9c0d20

https://access.redhat.com/errata/RHSA-2021:0637

https://bugzilla.redhat.com/show_bug.cgi?id=1837444

https://bugzilla.redhat.com/show_bug.cgi?id=1849003

https://bugzilla.redhat.com/show_bug.cgi?id=1873346

https://bugzilla.redhat.com/show_bug.cgi?id=1879407

https://bugzilla.redhat.com/show_bug.cgi?id=1889972

https://bugzilla.redhat.com/show_bug.cgi?id=1895939

https://bugzilla.redhat.com/show_bug.cgi?id=1895940

https://bugzilla.redhat.com/show_bug.cgi?id=1895941

https://bugzilla.redhat.com/show_bug.cgi?id=1895945

https://bugzilla.redhat.com/show_bug.cgi?id=1895946

https://bugzilla.redhat.com/show_bug.cgi?id=1895947

https://bugzilla.redhat.com/show_bug.cgi?id=1903699

https://bugzilla.redhat.com/show_bug.cgi?id=1903702

https://bugzilla.redhat.com/show_bug.cgi?id=1918392

https://bugzilla.redhat.com/show_bug.cgi?id=1920567

https://bugzilla.redhat.com/show_bug.cgi?id=1921353

https://bugzilla.redhat.com/show_bug.cgi?id=1924614

https://bugzilla.redhat.com/show_bug.cgi?id=1924811

https://bugzilla.redhat.com/show_bug.cgi?id=1929170

https://bugzilla.redhat.com/show_bug.cgi?id=1929216

https://access.redhat.com/security/updates/classification/#important

Plugin Details

Severity: High

ID: 147013

File Name: redhat-RHSA-2021-0637.nasl

Version: 1.17

Type: local

Agent: unix

Published: 3/3/2021

Updated: 11/7/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2021-21605

CVSS v3

Risk Factor: High

Base Score: 8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:jenkins-2-plugins, p-cpe:/a:redhat:enterprise_linux:python2-rsa, p-cpe:/a:redhat:enterprise_linux:jenkins, p-cpe:/a:redhat:enterprise_linux:python-rsa

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/3/2021

Vulnerability Publication Date: 5/14/2020

Reference Information

CVE: CVE-2020-11979, CVE-2020-1945, CVE-2020-2304, CVE-2020-2305, CVE-2020-2306, CVE-2020-2307, CVE-2020-2308, CVE-2020-2309, CVE-2020-25658, CVE-2021-21602, CVE-2021-21603, CVE-2021-21604, CVE-2021-21605, CVE-2021-21606, CVE-2021-21607, CVE-2021-21608, CVE-2021-21609, CVE-2021-21610, CVE-2021-21611

CWE: 20, 200, 377, 385, 502, 59, 611, 770, 79, 862, 863

IAVA: 2020-A-0324, 2021-A-0035-S, 2021-A-0039-S, 2021-A-0196

RHSA: 2021:0637