Bug 1711533

Summary: Unprivileged access to discovery
Product: OpenShift Container Platform Reporter: Maciej Szulik <maszulik>
Component: apiserver-authAssignee: Stefan Schimanski <sttts>
Status: CLOSED ERRATA QA Contact: Wei Sun <wsun>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 4.2.0CC: adam.kaplan, aos-bugs, ccoleman, gblomqui, mfojtik, nagrawal, sttts
Target Milestone: ---   
Target Release: 4.2.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-10-16 06:29:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1729522    
Bug Blocks:    

Description Maciej Szulik 2019-05-18 12:47:47 UTC
In https://github.com/openshift/origin/pull/22833/commits/50872400c21124bf825b4663ac720106f5aba351 we restored unprivileged access to system:discovery role, which was there in 4.1. We need to revert that change to be compatible with upstream, which fixed this in response to a CVE.

Comment 2 Mo 2019-06-01 11:58:55 UTC
Moving back to assigned as I need to add an e2e test to confirm this never regresses in the future.

Comment 6 Adam Kaplan 2019-07-12 13:32:55 UTC
Added #1729552 as a blocker for this issue.

Comment 21 errata-xmlrpc 2019-10-16 06:29:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:2922