Lucene search

K
redhatRedHatRHSA-2023:0772
HistoryFeb 20, 2023 - 6:24 p.m.

(RHSA-2023:0772) Moderate: OpenShift Container Platform 4.12.4 security update

2023-02-2018:24:31
access.redhat.com
13
red hat microshift
kubernetes orchestration
security update
cve-2022-3162
rpm packages
container images
edge device deployment
single-node clusters
release notes

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

48.1%

Red Hat build of MicroShift is Red Hat’s light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments.

This advisory contains the RPM packages for Red Hat build of MicroShift 4.12.4. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2023:0769

Security Fix(es):

  • kubernetes: Unauthorized read of Custom Resources (CVE-2022-3162)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All the bug fixes may not be documented in this advisory. See the following release notes documentation for details about these changes:

https://access.redhat.com/documentation/en-us/microshift/4.12/html/release_notes/index

All Red Hat build of MicroShift 4.12 users are advised to use these updated packages and images when they are available in the RPM repository.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

48.1%