Bug 2225633

Summary: Porting the vulnerability( CVE-2023-2253) on the version which is supported currently (i.e OCP 4.10 and 4.12)
Product: Red Hat OpenStack Reporter: Gandhimathy <gandhi.srini>
Component: openstack-containersAssignee: OSP Team <rhos-maint>
Status: CLOSED NOTABUG QA Contact: Arik Chernetsky <achernet>
Severity: high Docs Contact:
Priority: unspecified    
Version: 8.0 (Liberty)CC: jjoyce, jschluet, m.andre
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-08-09 13:03:15 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Gandhimathy 2023-07-25 15:44:46 UTC
Description of problem:

CVE-2023-2253 is reported in "github.com/docker/distribution	v0.0.0-20191216044856-a8371794149d"

This level is bundled with OSE package 4.12 through OPM.

The fix is provided in 4.13 through errata.
https://access.redhat.com/errata/RHSA-2023:4091

Looking for the timeline when will it be ported back to 4.12.

Comment 1 Jon Schlueter 2023-08-02 12:24:49 UTC
I think this should likely be filed against OpenShift unless there is something that I am missing that relates to OpenStack.

Comment 2 Gandhimathy 2023-08-07 07:28:57 UTC
It is not fixed in the OSE 4.12.
Reported at:
CVE-2023-2253

go	github.com/docker/distribution	v0.0.0-20191216044856-a8371794149d			
Fixed in:
fixed in 2.8.0	

github.com/docker/distribution	v0.0.0-20191216044856-a8371794149d			
Fixed in : fixed in 2.8.2-beta.1	go

Comment 3 Jason Joyce 2023-08-09 13:03:15 UTC
This issue needs to be filed with OpenShift at https://issues.redhat.com/projects/OCPBUGS/issues instead of OpenStack. Closing this as not a bug.