Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in Red Hat OpenShift for Windows Containers 9.0.1
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in Red Hat OpenShift for Windows Containers 9.0.1
ID: RHSA-2024:1203
Distribution: Red Hat
Plattformen: Red Hat OpenShift Container Platform 4.14
Datum: Do, 7. März 2024, 19:16
Referenzen: https://access.redhat.com/errata/RHSA-2024:1203
https://bugzilla.redhat.com/show_bug.cgi?id=2247163
https://issues.redhat.com/browse/OCPBUGS-27046
https://issues.redhat.com/browse/OCPBUGS-22984
https://issues.redhat.com/browse/OCPBUGS-27045
https://issues.redhat.com/browse/OCPBUGS-24748
https://issues.redhat.com/browse/OCPBUGS-28847
https://issues.redhat.com/browse/OCPBUGS-27240
https://access.redhat.com/security/cve/CVE-2023-5528
https://issues.redhat.com/browse/OCPBUGS-28226
Applikationen: Red Hat OpenShift for Windows Containers 9.0.1

Originalnachricht

The components for Red Hat OpenShift for Windows Containers 9.0.1 are now
available. This product release includes bug fixes and security updates for the following packages: windows-machine-config-operator and
windows-machine-config-operator-bundle.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Red Hat OpenShift for Windows Containers allows you to deploy Windows container
workloads running on Windows Server containers.

Security Fix(es):

* kubernetes: Insufficient input sanitization in in-tree storage plugin leads
to privilege escalation on Windows nodes (CVE-2023-5528)

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2023-5528: Improper Input Validation (CWE-20)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung