Uploaded image for project: 'OpenShift SDN'
  1. OpenShift SDN
  2. SDN-5477

Impact OpenShift 4.14.40 downgrades libreswan to an older version with CVE exposure

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Done
    • Icon: Critical Critical
    • None
    • None
    • None
    • False
    • None
    • False
    • ---
    • 0
    • 0

      Impact statement for the OCPBUGS-44379 series:

      Which 4.y.z to 4.y'.z' updates increase vulnerability?

      • Customers upgrading from any 4.13 or 4.14.z to 4.14.40 with IPSec enabled
      • A fresh installation of 4.14 with IPsec configured (spec.defaultNetwork.ovnKubernetesConfig.ipsecConfig: {})

      Which types of clusters?

      • IPSec OCP enabled clusters

      What is the impact? Is it serious enough to warrant removing update recommendations?

      How involved is remediation?

      Is this a regression?

      • Yes, this regression was introduced by pinning the libreswan package in ovnk container on 4.14.40 

       

              zshi@redhat.com Zenghui Shi
              trking W. Trevor King
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: