The vendor explicitly identifies these products or versions as containing the fix.
- openshift4/ose-prometheus@sha256:4292e3aac0c4439f99b0174707d7d5c5af3b727707a6b15640f1e24270a8e49e_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-prometheus@sha256:7b9df616545a7de600b17333fa73cb7826fed8bb65aaaa4b924bcd69fbbe7570_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-prometheus@sha256:f5cddce3a3415472fc98bef0150ab787f06b663fa53bd9ac023d52de9e857460_s390x as a component of Red Hat OpenShift Container Platform 4.8
- Summary
- An open redirect vulnerability was found in Prometheus. By specially crafted URL and a /new endpoint, an attacker can redirect user to any other URL.
- Remediation
- For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html
