[RHSA-2016:1836-01] Moderate: Red Hat OpenShift Enterprise Kibana security update

[email protected]
Newsgroups gmane.linux.redhat.enterprise.announce
Message-ID <201609081626.u88GQHUM014913@int-mx11.intmail.prod.int.phx2.redhat.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift Enterprise Kibana security update
Advisory ID:       RHSA-2016:1836-01
Product:           Red Hat OpenShift Enterprise
Advisory URL:      https://access.redhat.com/errata/RHSA-2016:1836
Issue date:        2016-09-08
=====================================================================

1. Summary:

An update for Red Hat OpenShift Enterprise Kibana images is now available.

Red Hat Product Security has rated this update as having a security impact 
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from 
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat OpenShift Enterprise 3.1 - noarch, x86_64
Red Hat OpenShift Enterprise 3.2 - noarch, x86_64

3. Description:

OpenShift Enterprise by Red Hat is the company's cloud computing Platform-
as-a-Service (PaaS) solution designed for on-premise or private cloud 
deployments.

Security Fix(es):

* A flaw was found in Kibana's logging functionality. If custom logging 
output was configured in Kibana, private user data could be written to the 
Kibana log files. A system attacker could use this data to hijack sessions 
of other users when using Kibana behind some form of authentication such as
Shield.

* A cross-site scripting (XSS) flaw was found in Kibana. A remote attacker 
could use this flaw to inject arbitrary web script into pages served to 
other users.

4. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

The following images are included in this errata:

openshift3/logging-kibana:3.1.1-10
openshift3/logging-elasticsearch:3.1.1-14
openshift3/logging-kibana:3.2.1-5
openshift3/logging-elasticsearch:3.2.1-7

5. Bugs fixed (https://bugzilla.redhat.com/):

1364389 - kibana: XSS vulnerability
1364394 - kibana: Session hijack via stealing cookies and auth headers from log

6. Package List:

Red Hat OpenShift Enterprise 3.1:

Source:
kibana-4.1.11-1.el7.src.rpm
openshift-elasticsearch-plugin-0.16.0.redhat_1-1.el7.src.rpm

noarch:
openshift-elasticsearch-plugin-0.16.0.redhat_1-1.el7.noarch.rpm

x86_64:
kibana-4.1.11-1.el7.x86_64.rpm
kibana-debuginfo-4.1.11-1.el7.x86_64.rpm

Red Hat OpenShift Enterprise 3.2:

Source:
kibana-4.1.11-1.el7.src.rpm
openshift-elasticsearch-plugin-0.16.0.redhat_1-1.el7.src.rpm

noarch:
openshift-elasticsearch-plugin-0.16.0.redhat_1-1.el7.noarch.rpm

x86_64:
kibana-4.1.11-1.el7.x86_64.rpm
kibana-debuginfo-4.1.11-1.el7.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is <[email protected]>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2016 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iD8DBQFX0ZEgXlSAg2UNWIIRAiE+AJ46vz5Jo5yLR2y7TdOEhUMjwqkNsgCcDwiL
k1FicvFYFudR0nOZ47fNlGw=
=hSkW
-----END PGP SIGNATURE-----


-- 
Enterprise-watch-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/enterprise-watch-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.