Red Hat Ceph Storage (RHCS) 4.2 has shipped fixes to two 'Important' CVEs and one 'Moderate' CVE at Ceph = RHSA-2021:0083 - Security Advisory == https://access.redhat.com/errata/RHSA-2021:0083 = CVE-2020-1971 == https://access.redhat.com/security/cve/CVE-2020-1971 == Important Impact = CVE-2020-13379 == https://access.redhat.com/security/cve/CVE-2020-13379 == Important Impact = CVE-2020-24659 == https://access.redhat.com/security/cve/CVE-2020-24659 == Moderate Impact = Impacted OCS 4.x Container images == Ceph CSI == Rook Ceph Operator The fixes to the CVEs at RHCS 4.2 are to be included at OCS through update of the associated OCS container images to Red Hat Ceph Storage 4.2 or higher
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Red Hat OpenShift Container Storage 4.6.3 container bug fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2021:0718