Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2019:2989 - Security Advisory
Issued:
2019-10-14
Updated:
2019-10-14

RHSA-2019:2989 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: OpenShift Container Platform 3.10 atomic-openshift kube-apiserver security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for atomic-openshift kube-apiserver is now available for Red Hat OpenShift Container Platform 3.10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.

Security Fix(es):

  • atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository (CVE-2019-10150)
  • containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure (CVE-2019-10214)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For OpenShift Container Platform 3.10 see the following documentation,
which will be updated shortly for release 3.10.175, for important
instructions on how to upgrade your cluster and fully apply this
asynchronous errata update:

https://docs.openshift.com/container-platform/3.10/release_notes/ocp_3_10_release_notes.html

Affected Products

  • Red Hat OpenShift Container Platform 3.10 x86_64
  • Red Hat OpenShift Container Platform for Power 3.10 ppc64le

Fixes

  • BZ - 1713433 - CVE-2019-10150 atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository
  • BZ - 1732508 - CVE-2019-10214 containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure

CVEs

  • CVE-2019-10150
  • CVE-2019-10214

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Container Platform 3.10

SRPM
atomic-openshift-3.10.175-1.git.0.f9f0e81.el7.src.rpm SHA-256: 1aa890784d3dfa9379c5e6452ab6d71b72eeeb4a045703af2bb3d313471dcae8
cri-o-1.10.6-2.rhaos3.10.git56d7d9a.el7.src.rpm SHA-256: 83267ab735764b76a4a5df30902bcbe80dc52aafbf2867bfd0ea6733efab32c5
x86_64
atomic-openshift-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: beede1347fe4f93e1cfc94fbdf5ccafe556def75fdad03bee4e2d1c78149db1e
atomic-openshift-clients-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 8d03db9a7a5caf35e6167eab78336cc22314e68c5b59d1c97a07b533d4fd6cc1
atomic-openshift-clients-redistributable-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 519bfa3bc2ce5c873fc5081decf6285f76461919b33c4242509f54ad2e2c83c8
atomic-openshift-docker-excluder-3.10.175-1.git.0.f9f0e81.el7.noarch.rpm SHA-256: b4267a94cdbb65935951cd0919a8636cf58764a8454714494a373dad915de2d8
atomic-openshift-excluder-3.10.175-1.git.0.f9f0e81.el7.noarch.rpm SHA-256: e66f2c0f8b8eb1b10fe9a4e6f27cbc2f613e1c91a1cabc8740f194dd6096a65b
atomic-openshift-hyperkube-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 0eec9e6613a4290b09403e9e22a95bed3afe619e70a53b52b2c99ac76553ae8c
atomic-openshift-hypershift-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 6d7629c19e941f69d3a1a6b5a55c473b086039eccdf8170749592b783e336744
atomic-openshift-master-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 337b48e5e44f157e4bd733aef7e678b502e12c21c357f43f34b9082f293d2044
atomic-openshift-node-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: d76b2ab1666592623357c3234e956fd8e8416a738b787b722d8ad2eba2f97bc4
atomic-openshift-pod-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 7cd697ca53a75d8306675d3bb7ffae0c3d543af14b7198a5ac7f6e09ff0efe9e
atomic-openshift-sdn-ovs-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 0929f8d80c370cc406d095c5336b6c6bcd1c3ddfc68e6a14c6a7c72eb9cf2a00
atomic-openshift-template-service-broker-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: d18ac62a9b5cc983a567014d0437af41bd783b4c5df53b8457576ab0697984e2
atomic-openshift-tests-3.10.175-1.git.0.f9f0e81.el7.x86_64.rpm SHA-256: 6a9a1bef85d68953eb418c70a193cd16b9302de1a25c34158652235e52d47893
cri-o-1.10.6-2.rhaos3.10.git56d7d9a.el7.x86_64.rpm SHA-256: f8b87cd2330132492f56bc28ebcc902f95a63cca9059381d1b6180bbf28201b1

Red Hat OpenShift Container Platform for Power 3.10

SRPM
atomic-openshift-3.10.175-1.git.0.f9f0e81.el7.src.rpm SHA-256: 1aa890784d3dfa9379c5e6452ab6d71b72eeeb4a045703af2bb3d313471dcae8
cri-o-1.10.6-2.rhaos3.10.git56d7d9a.el7.src.rpm SHA-256: 83267ab735764b76a4a5df30902bcbe80dc52aafbf2867bfd0ea6733efab32c5
ppc64le
atomic-openshift-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: af4b9215b483b8f5f897e0c7a03130b6cdd1db68b640287b360d22ec86acaf20
atomic-openshift-clients-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: 8707886fe041f236ec237298613b95cfedc785c55bb58797f8ce8314c42071fc
atomic-openshift-docker-excluder-3.10.175-1.git.0.f9f0e81.el7.noarch.rpm SHA-256: b4267a94cdbb65935951cd0919a8636cf58764a8454714494a373dad915de2d8
atomic-openshift-excluder-3.10.175-1.git.0.f9f0e81.el7.noarch.rpm SHA-256: e66f2c0f8b8eb1b10fe9a4e6f27cbc2f613e1c91a1cabc8740f194dd6096a65b
atomic-openshift-hyperkube-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: 860395b8f1ecfcefd3473cbd1bfaf40a3a232202a44a1e689dc03a932529e7c9
atomic-openshift-hypershift-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: 3d9a8f4a0df22568da56c19a19404e2f74c421067040dd5768cd08e3c42cffe8
atomic-openshift-master-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: e7eee8220b732891dd608b38ca04cd32979c2bfd44b1b7d60fa721725fef58dd
atomic-openshift-node-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: 3af8eb3b7ea0a2b27dc69c9e7a5d5c38924737e3dcb728cdffdc00a727acb581
atomic-openshift-pod-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: f2740cabb4986a91acf3634c7dffb94ef5132e84d4b1e1404decc9fa561da10d
atomic-openshift-sdn-ovs-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: 2ab2929b4bbbc70f2eb82aa3f91c5ede351daf25efeb7a83e89bc68be71436ff
atomic-openshift-template-service-broker-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: 173d67839469e712f15a918c55347313a0b7737aff477671770230da2d8b016f
atomic-openshift-tests-3.10.175-1.git.0.f9f0e81.el7.ppc64le.rpm SHA-256: edfafeaa1eba6e1484cb1652ff3aed1c7ffa0b9a7a76e8a1dfa67085bffa2840
cri-o-1.10.6-2.rhaos3.10.git56d7d9a.el7.ppc64le.rpm SHA-256: 639b55fae6f08dede78fa4c49c3656cf0a6675f002fc7014dd939f01ab2d9abe

The Red Hat security contact is [email protected]. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility