Bug 2225633 - Porting the vulnerability( CVE-2023-2253) on the version which is supported currently (i.e OCP 4.10 and 4.12)
Summary: Porting the vulnerability( CVE-2023-2253) on the version which is supported c...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-containers
Version: 8.0 (Liberty)
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
: ---
Assignee: OSP Team
QA Contact: Arik Chernetsky
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-07-25 15:44 UTC by Gandhimathy
Modified: 2023-08-09 13:03 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-08-09 13:03:15 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker OSP-26891 0 None None None 2023-07-25 15:45:47 UTC

Description Gandhimathy 2023-07-25 15:44:46 UTC
Description of problem:

CVE-2023-2253 is reported in "github.com/docker/distribution	v0.0.0-20191216044856-a8371794149d"

This level is bundled with OSE package 4.12 through OPM.

The fix is provided in 4.13 through errata.
https://access.redhat.com/errata/RHSA-2023:4091

Looking for the timeline when will it be ported back to 4.12.

Comment 1 Jon Schlueter 2023-08-02 12:24:49 UTC
I think this should likely be filed against OpenShift unless there is something that I am missing that relates to OpenStack.

Comment 2 Gandhimathy 2023-08-07 07:28:57 UTC
It is not fixed in the OSE 4.12.
Reported at:
CVE-2023-2253

go	github.com/docker/distribution	v0.0.0-20191216044856-a8371794149d			
Fixed in:
fixed in 2.8.0	

github.com/docker/distribution	v0.0.0-20191216044856-a8371794149d			
Fixed in : fixed in 2.8.2-beta.1	go

Comment 3 Jason Joyce 2023-08-09 13:03:15 UTC
This issue needs to be filed with OpenShift at https://issues.redhat.com/projects/OCPBUGS/issues instead of OpenStack. Closing this as not a bug.


Note You need to log in before you can comment on or make changes to this bug.