RedHat: RHSA-2021-0100:01 Moderate: OpenShift Container Platform 4.7
Summary
The file-integrity-operator image update is now available for OpenShift
Container Platform 4.7.
Security Fix(es):
* golang-github-gorilla-websocket: integer overflow leads to denial of
service (CVE-2020-27813)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2020-27813 https://access.redhat.com/security/updates/classification/#moderate
Package List
Topic
The file-integrity-operator image update is now available for OpenShiftContainer Platform 4.7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
1826301 - Wrong NodeStatus reports in file-integrity scan when configuration error in aide.conf file
1869293 - The configmap name looks confusing in aide-ds pod logs
1902111 - CVE-2020-27813 golang-github-gorilla-websocket: integer overflow leads to denial of service
1905011 - The file-integrity-Operator brew Bundle image does not available for OCP4.7
1910050 - [OCP v47] The file integrity aide-ds pod goes in CrashLoopBackOff state during the scan
1921692 - Please report fileintegritynodestatus (active/ failed / etc) in column when running `oc get fileintegritynodestatus`
1923096 - The daemonSet does not get updated when the nodeSelector and Tolerations get changed in fileIntegrity object