Red Hat released security updates for OpenShift Container Platform (OCP) 4.14.32 and 4.15.20 that remediate CVE-2024-5037, an issuer-validation bypass affecting OpenShift Telemetry JWT authentication, and CVE-2023-48795 (Terrapin), an SSH Binary Packet Protocol prefix-truncation vulnerability. The Important-severity updates provide refreshed container images for supported OCP deployments on RHEL 8 and RHEL 9 across x86_64, s390x, ppc64le, and aarch64 architectures; Red Hat advises customers to upgrade through their applicable release channel using the OpenShift CLI or web console.
Red Hat also shipped OCP 4.15.0 packages and images addressing security issues in bundled Go and OpenTelemetry components, including XSS, denial-of-service, go-git path traversal and potential remote-code-execution risks, as well as Terrapin. Until SSH updates can be deployed, organizations can verify Terrapin protection by confirming clients advertise kex-strict-c-v00@openssh.com and servers return kex-strict-s-v00@openssh.com; temporary RHEL crypto-policy restrictions can disable affected ChaCha20-Poly1305 and encrypt-then-MAC algorithms, though they may reduce interoperability.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2024:4959 for OpenShift Container Platform 4.14.34, updating packages to remediate the goproxy denial-of-service vulnerability CVE-2023-37788 and the SSH Terrapin vulnerability CVE-2023-48795. A separate RHSA-2024:4960 advisory covered associated container images.
Red Hat issued RHSA-2024:4329, an Important-severity OpenShift Container Platform 4.14.32 update. The release updated Kubernetes to 1.27.15 and fixed CVE-2024-5037, CVE-2023-48795, and other vulnerabilities in updated release components.
Red Hat issued Important-severity advisory RHSA-2024:4156 for OpenShift Container Platform 4.16.1, providing updated container images for supported RHEL 9 architectures. The release fixes the telemeter JWT issuer-validation bypass (CVE-2024-5037) and a Helm panic caused by missing YAML content (CVE-2024-26147).
Red Hat issued RHSA-2024:4151, an Important-severity OpenShift Container Platform 4.15.20 update with container images, fixes for the Telemetry JWT issuer-validation bypass (CVE-2024-5037) and SSH Terrapin issue (CVE-2023-48795), plus additional fixes.
Red Hat issued Moderate-severity advisory RHSA-2024:3918 for OpenShift Container Platform 4.14.30, updating packages to remediate the SSH Binary Packet Protocol prefix-truncation vulnerability CVE-2023-48795. Separate advisory RHSA-2024:3881 covered the associated container images.
Red Hat issued Critical advisory RHSA-2024:1557 for OpenShift Builds 1.0, providing updated component images across x86_64, ppc64le, s390x, and aarch64 architectures. The update addressed the SSH Terrapin flaw CVE-2023-48795 and go-git vulnerabilities CVE-2023-49569 (path traversal and potential remote code execution) and CVE-2023-49568 (denial of service), among other flaws.
Red Hat issued Important-severity advisory RHSA-2024:0954 for OpenShift for Windows Containers 10.15.0 on OpenShift Container Platform 4.15 for RHEL 9 x86_64. The update remediated HTTP/2 rapid-reset flaws, the Kubernetes Windows-node privilege-escalation flaw CVE-2023-5528, CVE-2023-48795, and a Windows Machine Config Operator defect that approved all node certificate signing requests.
Red Hat published RHSA-2023:7197 for OpenShift Container Platform 4.15.0, supplying updated RPM packages and addressing vulnerabilities in Go, OpenTelemetry, SSH, and go-git components, including CVE-2023-48795. A separate RHSA-2023:7198 advisory covered the associated container images.
Red Hat documented verification of the CVE-2023-48795 SSH strict key-exchange protection and temporary workarounds for unpatched RHEL systems, including disabling ChaCha20-Poly1305 and encrypt-then-MAC algorithms on RHEL 8 and 9. It recommended applying full updates rather than relying on the temporary mitigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.