-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: OpenShift Container Platform 4.5 container image security update
Advisory ID: RHSA-2020:2412-01
Product: Red Hat OpenShift Enterprise
Advisory URL: https://access.redhat.com/errata/RHSA-2020:2412
Issue date: 2020-07-13
CVE Names: CVE-2019-11254 CVE-2019-11358 CVE-2020-8558
CVE-2020-9283 CVE-2020-10749 CVE-2020-11022
CVE-2020-11023
====================================================================
1. Summary:
An update is now available for Red Hat OpenShift Container Platform 4.5.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
Security Fix(es):
* golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys
allowed for panic (CVE-2020-9283)
* kubernetes: Denial of service in API server via crafted YAML payloads by
authorized users (CVE-2019-11254)
* js-jquery: prototype pollution in object's prototype led to denial of
service or remote code execution or property injection (CVE-2019-11358)
* kubernetes: node localhost services reachable via martian packets
(CVE-2020-8558)
* containernetworking/plugins: IPv6 router advertisements allowed for MitM
attacks on IPv4 clusters (CVE-2020-10749)
* jquery: Cross-site scripting due to improper injQuery.htmlPrefilter
method (CVE-2020-11022)
* jQuery: passing HTML containing