Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-63600

Add the title and the priority of the fixes at the Security Advisory

XMLWordPrintable

    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Important
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Security Advisories now only display the issue ID, omitting the issue title. This lack of context increases the time required to assess which advisories are relevant to customer environments. Providing the severity level alongside the ID would also greatly assist in prioritization.

      Version-Release number of selected component (if applicable):

          from 4.16 and greater versions

      How reproducible:

          Go to the OCP 4.16 RN , at "Asynchronous errata updates" , check for the latest z-stream which should have a reference of the advisory that include the list of bug fixes. For instance, at 4.16.50:
      ~~~
      1.9.1. RHSA-2025:17690 - OpenShift Container Platform 4.16.50 bug fix and security update:
      Issued: 15 October 2025
      OpenShift Container Platform release 4.16.50 is now available. The 
      list of bug fixes that are included in the update is documented in the RHSA-2025:17690 advisory.
      				
      Open the https://access.redhat.com/errata/RHSA-2025:17690, check the list of Fixes

      Actual results:

      Fixes
      https://bugzilla.redhat.com/show_bug.cgi?id=2331720
      https://issues.redhat.com/browse/OCPBUGS-59162
      https://issues.redhat.com/browse/OCPBUGS-59931
      ...
      https://issues.redhat.com/browse/OCPBUGS-62707
      
      
      

      Expected results:

      Links with Title of the issues and as enhancement the priority of the fix, for instance:
      ~~~ 
        Fixes 
      * Bug 2331720 (CVE-2024-45337) - CVE-2024-45337 golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto [High]
      
      * nip.io no longer is available causing installer vsphere unit tests to fail [Normal]
      
      * after OVN-K live migration br0 is still present [Important]
       
      ... 
      
      * Fix oauth-proxy e2e-component tests [None]
      ~~~

       

      Additional info:

          This was the format before since a couple of mount it has changed.

              ocp-docs-bot OCP DocsBot
              rhn-support-pescorza Pamela Lizeth Escorza Gil
              None
              None
              None
              None
              Votes:
              1 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: