Vulnerability Database
Blog
FAQ
Docs
RHSA-2019:3906
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2019:3906
Import Source
https://security.access.redhat.com/data/osv/RHSA-2019:3906.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2019:3906
Related
CVE-2019-9512
CVE-2019-9514
Published
2024-09-20T13:54:11Z
Modified
2024-10-09T06:53:44Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: OpenShift Container Platform 3.11 HTTP/2 security update
Details
References
https://access.redhat.com/errata/RHSA-2019:3906
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=1735645
https://bugzilla.redhat.com/show_bug.cgi?id=1735744
https://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_3906.json
https://access.redhat.com/security/cve/CVE-2019-9512
https://www.cve.org/CVERecord?id=CVE-2019-9512
https://nvd.nist.gov/vuln/detail/CVE-2019-9512
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
https://groups.google.com/forum/#!topic/golang-announce/65QixT3tcmg
https://groups.google.com/forum/#!topic/kubernetes-security-announce/wlHLHit1BqA
https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
https://www.mail-archive.com/grpc-io@googlegroups.com/msg06408.html
https://access.redhat.com/security/cve/CVE-2019-9514
https://www.cve.org/CVERecord?id=CVE-2019-9514
https://nvd.nist.gov/vuln/detail/CVE-2019-9514
Affected packages
Red Hat:openshift:3.11::el7
/
atomic-enterprise-service-catalog
Package
Name
atomic-enterprise-service-catalog
Purl
pkg:rpm/redhat/atomic-enterprise-service-catalog
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.11.154-1.git.1.fa68ced.el7
Red Hat:openshift:3.11::el7
/
atomic-enterprise-service-catalog-svcat
Package
Name
atomic-enterprise-service-catalog-svcat
Purl
pkg:rpm/redhat/atomic-enterprise-service-catalog-svcat
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:3.11.154-1.git.1.fa68ced.el7
Red Hat:openshift:3.11::el7
/
atomic-openshift-cluster-autoscaler
Package
Name
atomic-openshift-cluster-autoscaler
Purl
pkg:rpm/redhat/atomic-openshift-cluster-autoscaler
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.532da7a.el7
Red Hat:openshift:3.11::el7
/
atomic-openshift-descheduler
Package
Name
atomic-openshift-descheduler
Purl
pkg:rpm/redhat/atomic-openshift-descheduler
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.1d31032.el7
Red Hat:openshift:3.11::el7
/
atomic-openshift-metrics-server
Package
Name
atomic-openshift-metrics-server
Purl
pkg:rpm/redhat/atomic-openshift-metrics-server
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.6a6b6ce.el7
Red Hat:openshift:3.11::el7
/
atomic-openshift-node-problem-detector
Package
Name
atomic-openshift-node-problem-detector
Purl
pkg:rpm/redhat/atomic-openshift-node-problem-detector
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.5e8e065.el7
Red Hat:openshift:3.11::el7
/
atomic-openshift-service-idler
Package
Name
atomic-openshift-service-idler
Purl
pkg:rpm/redhat/atomic-openshift-service-idler
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.f80fb86.el7
Red Hat:openshift:3.11::el7
/
atomic-openshift-web-console
Package
Name
atomic-openshift-web-console
Purl
pkg:rpm/redhat/atomic-openshift-web-console
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.f54cb18.el7
Red Hat:openshift:3.11::el7
/
cockpit
Package
Name
cockpit
Purl
pkg:rpm/redhat/cockpit
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:195-2.rhaos.el7
Red Hat:openshift:3.11::el7
/
cockpit-debuginfo
Package
Name
cockpit-debuginfo
Purl
pkg:rpm/redhat/cockpit-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:195-2.rhaos.el7
Red Hat:openshift:3.11::el7
/
cockpit-kubernetes
Package
Name
cockpit-kubernetes
Purl
pkg:rpm/redhat/cockpit-kubernetes
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:195-2.rhaos.el7
Red Hat:openshift:3.11::el7
/
csi-attacher
Package
Name
csi-attacher
Purl
pkg:rpm/redhat/csi-attacher
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2.0-4.git27299be.el7
Red Hat:openshift:3.11::el7
/
csi-attacher-debuginfo
Package
Name
csi-attacher-debuginfo
Purl
pkg:rpm/redhat/csi-attacher-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2.0-4.git27299be.el7
Red Hat:openshift:3.11::el7
/
csi-driver-registrar
Package
Name
csi-driver-registrar
Purl
pkg:rpm/redhat/csi-driver-registrar
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2.0-2.el7
Red Hat:openshift:3.11::el7
/
csi-driver-registrar-debuginfo
Package
Name
csi-driver-registrar-debuginfo
Purl
pkg:rpm/redhat/csi-driver-registrar-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2.0-2.el7
Red Hat:openshift:3.11::el7
/
csi-livenessprobe
Package
Name
csi-livenessprobe
Purl
pkg:rpm/redhat/csi-livenessprobe
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.1-2.gitff5b6a0.el7
Red Hat:openshift:3.11::el7
/
csi-livenessprobe-debuginfo
Package
Name
csi-livenessprobe-debuginfo
Purl
pkg:rpm/redhat/csi-livenessprobe-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.1-2.gitff5b6a0.el7
Red Hat:openshift:3.11::el7
/
csi-provisioner
Package
Name
csi-provisioner
Purl
pkg:rpm/redhat/csi-provisioner
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2.0-3.el7
Red Hat:openshift:3.11::el7
/
csi-provisioner-debuginfo
Package
Name
csi-provisioner-debuginfo
Purl
pkg:rpm/redhat/csi-provisioner-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2.0-3.el7
Red Hat:openshift:3.11::el7
/
golang-github-openshift-oauth-proxy
Package
Name
golang-github-openshift-oauth-proxy
Purl
pkg:rpm/redhat/golang-github-openshift-oauth-proxy
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.220e3dc.el7
Red Hat:openshift:3.11::el7
/
golang-github-openshift-prometheus-alert-buffer
Package
Name
golang-github-openshift-prometheus-alert-buffer
Purl
pkg:rpm/redhat/golang-github-openshift-prometheus-alert-buffer
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0-3.gitceca8c1.el7
Red Hat:openshift:3.11::el7
/
golang-github-prometheus-alertmanager
Package
Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/redhat/golang-github-prometheus-alertmanager
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.4acd2e6.el7
Red Hat:openshift:3.11::el7
/
golang-github-prometheus-node_exporter
Package
Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/redhat/golang-github-prometheus-node_exporter
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.bc9f224.el7
Red Hat:openshift:3.11::el7
/
golang-github-prometheus-prometheus
Package
Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/redhat/golang-github-prometheus-prometheus
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.148db48.el7
Red Hat:openshift:3.11::el7
/
hawkular-openshift-agent
Package
Name
hawkular-openshift-agent
Purl
pkg:rpm/redhat/hawkular-openshift-agent
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.2.2-3.el7
Red Hat:openshift:3.11::el7
/
heapster
Package
Name
heapster
Purl
pkg:rpm/redhat/heapster
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.3.0-4.el7
Red Hat:openshift:3.11::el7
/
image-inspector
Package
Name
image-inspector
Purl
pkg:rpm/redhat/image-inspector
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.0-4.el7
Red Hat:openshift:3.11::el7
/
openshift-enterprise-autoheal
Package
Name
openshift-enterprise-autoheal
Purl
pkg:rpm/redhat/openshift-enterprise-autoheal
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.13199be.el7
Red Hat:openshift:3.11::el7
/
openshift-enterprise-cluster-capacity
Package
Name
openshift-enterprise-cluster-capacity
Purl
pkg:rpm/redhat/openshift-enterprise-cluster-capacity
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.5798c2c.el7
Red Hat:openshift:3.11::el7
/
openshift-eventrouter
Package
Name
openshift-eventrouter
Purl
pkg:rpm/redhat/openshift-eventrouter
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2-4.git7c289cc.el7
Red Hat:openshift:3.11::el7
/
openshift-eventrouter-debuginfo
Package
Name
openshift-eventrouter-debuginfo
Purl
pkg:rpm/redhat/openshift-eventrouter-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.2-4.git7c289cc.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage
Package
Name
openshift-external-storage
Purl
pkg:rpm/redhat/openshift-external-storage
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-cephfs-provisioner
Package
Name
openshift-external-storage-cephfs-provisioner
Purl
pkg:rpm/redhat/openshift-external-storage-cephfs-provisioner
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-debuginfo
Package
Name
openshift-external-storage-debuginfo
Purl
pkg:rpm/redhat/openshift-external-storage-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-efs-provisioner
Package
Name
openshift-external-storage-efs-provisioner
Purl
pkg:rpm/redhat/openshift-external-storage-efs-provisioner
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-local-provisioner
Package
Name
openshift-external-storage-local-provisioner
Purl
pkg:rpm/redhat/openshift-external-storage-local-provisioner
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-manila-provisioner
Package
Name
openshift-external-storage-manila-provisioner
Purl
pkg:rpm/redhat/openshift-external-storage-manila-provisioner
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-snapshot-controller
Package
Name
openshift-external-storage-snapshot-controller
Purl
pkg:rpm/redhat/openshift-external-storage-snapshot-controller
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
openshift-external-storage-snapshot-provisioner
Package
Name
openshift-external-storage-snapshot-provisioner
Purl
pkg:rpm/redhat/openshift-external-storage-snapshot-provisioner
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:0.0.2-9.gitd3c94f0.el7
Red Hat:openshift:3.11::el7
/
prometheus
Package
Name
prometheus
Purl
pkg:rpm/redhat/prometheus
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.148db48.el7
Red Hat:openshift:3.11::el7
/
prometheus-alertmanager
Package
Name
prometheus-alertmanager
Purl
pkg:rpm/redhat/prometheus-alertmanager
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.4acd2e6.el7
Red Hat:openshift:3.11::el7
/
prometheus-node-exporter
Package
Name
prometheus-node-exporter
Purl
pkg:rpm/redhat/prometheus-node-exporter
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:3.11.154-1.git.1.bc9f224.el7
RHSA-2019:3906 - OSV