RHCOS 4 : OpenShift Container Platform 4.8.56 (RHSA-2023:0017)

high Nessus Plugin ID 189418

Synopsis

The remote Red Hat CoreOS host is missing one or more security updates for OpenShift Container Platform 4.8.56.

Description

The remote Red Hat Enterprise Linux CoreOS 4 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0017 advisory.

- http2-server: Invalid HTTP/2 requests cause DoS (CVE-2022-2048)

- Libraries: Untrusted users can modify some Pipeline libraries in Pipeline Shared Groovy Libraries Plugin (CVE-2022-29047)

- plugin: Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Pipeline:
Groovy Plugin (CVE-2022-30945)

- plugin: CSRF vulnerability in Script Security Plugin (CVE-2022-30946)

- plugin: Mercurial SCM plugin can check out from the controller file system (CVE-2022-30948)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHCOS OpenShift Container Platform 4.8.56 packages based on the guidance in RHSA-2023:0017.

See Also

http://www.nessus.org/u?7299f845

https://access.redhat.com/security/updates/classification/#important

https://access.redhat.com/errata/RHSA-2023:0017

https://bugzilla.redhat.com/show_bug.cgi?id=2074855

https://bugzilla.redhat.com/show_bug.cgi?id=2103548

https://bugzilla.redhat.com/show_bug.cgi?id=2103551

https://bugzilla.redhat.com/show_bug.cgi?id=2114755

https://bugzilla.redhat.com/show_bug.cgi?id=2116840

https://bugzilla.redhat.com/show_bug.cgi?id=2116952

https://bugzilla.redhat.com/show_bug.cgi?id=2119642

https://bugzilla.redhat.com/show_bug.cgi?id=2119643

https://bugzilla.redhat.com/show_bug.cgi?id=2119644

https://bugzilla.redhat.com/show_bug.cgi?id=2119645

https://bugzilla.redhat.com/show_bug.cgi?id=2119646

https://bugzilla.redhat.com/show_bug.cgi?id=2119647

https://bugzilla.redhat.com/show_bug.cgi?id=2119653

https://bugzilla.redhat.com/show_bug.cgi?id=2119656

https://bugzilla.redhat.com/show_bug.cgi?id=2119657

https://bugzilla.redhat.com/show_bug.cgi?id=2119658

Plugin Details

Severity: High

ID: 189418

File Name: rhcos-RHSA-2023-0017.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 1/24/2024

Updated: 5/4/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-30945

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2022-36882

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:jenkins, cpe:/o:redhat:enterprise_linux:8:coreos, p-cpe:/a:redhat:enterprise_linux:jenkins-2-plugins

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 1/12/2023

Vulnerability Publication Date: 4/12/2022

Reference Information

CVE: CVE-2022-2048, CVE-2022-29047, CVE-2022-30945, CVE-2022-30946, CVE-2022-30948, CVE-2022-30952, CVE-2022-30953, CVE-2022-30954, CVE-2022-34174, CVE-2022-34176, CVE-2022-34177, CVE-2022-36881, CVE-2022-36882, CVE-2022-36883, CVE-2022-36884, CVE-2022-36885

CWE: 200, 208, 22, 288, 322, 352, 410, 435, 668, 693, 79, 862

RHSA: 2023:0017