{"id":27354,"date":"2022-07-22T01:28:11","date_gmt":"2022-07-21T21:28:11","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167778\/RHSA-2022-5673-01.txt"},"modified":"2022-07-22T11:36:27","modified_gmt":"2022-07-22T07:06:27","slug":"red-hat-security-advisory-2022-5673-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-5673-01\/","title":{"rendered":"Red Hat Security Advisory 2022-5673-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Important: Release of containers for OSP 16.2.z director operator tech preview<br \/>\nAdvisory ID: RHSA-2022:5673-01<br \/>\nProduct: Red Hat OpenStack Platform<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:5673<br \/>\nIssue date: 2022-07-20<br \/>\nCVE Names: CVE-2021-3634 CVE-2021-3737 CVE-2021-4189<br \/>\nCVE-2021-40528 CVE-2021-41103 CVE-2021-43565<br \/>\nCVE-2022-1271 CVE-2022-1621 CVE-2022-1629<br \/>\nCVE-2022-22576 CVE-2022-25313 CVE-2022-25314<br \/>\nCVE-2022-26945 CVE-2022-27774 CVE-2022-27776<br \/>\nCVE-2022-27782 CVE-2022-29824 CVE-2022-30321<br \/>\nCVE-2022-30322 CVE-2022-30323<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">Red Hat OpenStack Platform 16.2 (Train) director operator containers, with<br \/>\nseveral Important security fixes, are available for technology preview.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">Release osp-director-operator images<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* go-getter: unsafe download (issue 1 of 3) [Important] (CVE-2022-30321)<br \/>\n* go-getter: unsafe download (issue 2 of 3) [Important] (CVE-2022-30322)<br \/>\n* go-getter: unsafe download (issue 3 of 3) [Important] (CVE-2022-30323)<br \/>\n* go-getter: command injection vulnerability [Important] (CVE-2022-26945)<br \/>\n* golang.org\/x\/crypto: empty plaintext packet causes panic [Moderate]\n(CVE-2021-43565)<br \/>\n* containerd: insufficiently restricted permissions on container root and<br \/>\nplugin directories [Moderate] (CVE-2021-41103)<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">OSP 16.2 Release &#8211; OSP Director Operator Containers tech preview<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">2011007 &#8211; CVE-2021-41103 containerd: insufficiently restricted permissions on container root and plugin directories<br \/>\n2030787 &#8211; CVE-2021-43565 golang.org\/x\/crypto: empty plaintext packet causes panic<br \/>\n2092918 &#8211; CVE-2022-30321 go-getter: unsafe download (issue 1 of 3)<br \/>\n2092923 &#8211; CVE-2022-30322 go-getter: unsafe download (issue 2 of 3)<br \/>\n2092925 &#8211; CVE-2022-30323 go-getter: unsafe download (issue 3 of 3)<br \/>\n2092928 &#8211; CVE-2022-26945 go-getter: command injection vulnerability<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2021-3634<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3737<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4189<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-40528<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-41103<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43565<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1271<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1621<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1629<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22576<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25313<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25314<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26945<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27774<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27776<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27782<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-29824<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30321<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30322<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30323<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#important<br \/>\nhttps:\/\/access.redhat.com\/errata\/RHSA-2022:4991<br \/>\nhttps:\/\/access.redhat.com\/containers<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYtg1odzjgjWX9erEAQgLKhAAmNPdMhNGBxVdTDymf3EpM8xQcr25XWOR<br \/>\nwfdum3Q4\/Ji9\/IQJ1NCv\/5IsphsHgDaKlo9pY9BPzgeT4z90ga+5ldcXgqC9dk74<br \/>\nKVBUURmWxfbkg57E5dWHkMb9fxyRIpo0NiFlwLx5ynjIjO\/WwWwFzz4YIiktDy1H<br \/>\nAgGz1oZnX+hdZ+BpH2Ltx70cCyqvHgA+aOFXGHZNl8qQXQEjtCBN957XEo4c1hgp<br \/>\n6HBmK3GkcaL2Ml32\/EM+2j4BLyz4hUK9Xfe171le0RcjkIND9BNzx2055dXov9uY<br \/>\neN52pn7pL8BvWU37b39wZx4EEyluYfnnlLaM9I+Y0t0NFhtA2H5Xk\/hei1W3tzkP<br \/>\nFdSR6gYIB1wwkBKu\/qus4RqrtDEhYHOYXqIziEE+G0nF0ht1As7kLq7U05n7spOu<br \/>\n9mKht4iXLj17lzPHAXM5N9HF0\/v3WuVNQf1DXOzb29BUF14fGFzXCWp\/nIG+PpEt<br \/>\nefmBklT4DAgLaibGwKyLZ7YOcfl\/mQoQDCs3uPqpqeXf799cTtJFmC520ox\/eaFx<br \/>\nOFQ1ZNpDI\/FKi1919hl2Ox5V7OxOZRIs\/MPsLJ+HBtr9CmGMV2\/rezeTEu+cD7Ts<br \/>\nSFDt82MQeqSJuxjpa04odqcU6NZbccoF3c7sxn49Vvk6AAn6umXgJCR\/Pnp9QPZT<br \/>\n\/jnfjsj7xYM=<br \/>\n=+5tE<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Release of containers for OSP 16.2.z director operator tech preview Advisory ID: RHSA-2022:5673-01 Product: Red Hat OpenStack Platform Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:5673 Issue date: 2022-07-20 CVE Names: CVE-2021-3634 CVE-2021-3737 CVE-2021-4189 CVE-2021-40528 CVE-2021-41103 CVE-2021-43565 CVE-2022-1271 CVE-2022-1621 CVE-2022-1629 CVE-2022-22576 CVE-2022-25313 CVE-2022-25314 CVE-2022-26945 CVE-2022-27774 CVE-2022-27776 CVE-2022-27782 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-27354","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/27354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=27354"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/27354\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=27354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=27354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=27354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}