Show plain JSON{"affected_release": [{"advisory": "RHSA-2020:1230", "cpe": "cpe:/a:redhat:rhel_extras_other:7", "package": "skopeo-1:0.1.40-7.el7_8", "product_name": "Red Hat Enterprise Linux 7 Extras", "release_date": "2020-04-01T00:00:00Z"}, {"advisory": "RHSA-2020:1231", "cpe": "cpe:/a:redhat:rhel_extras_other:7", "package": "buildah-0:1.11.6-8.el7_8", "product_name": "Red Hat Enterprise Linux 7 Extras", "release_date": "2020-04-01T00:00:00Z"}, {"advisory": "RHSA-2020:1234", "cpe": "cpe:/a:redhat:rhel_extras_other:7", "package": "docker-2:1.13.1-161.git64e9980.el7_8", "product_name": "Red Hat Enterprise Linux 7 Extras", "release_date": "2020-04-01T00:00:00Z"}, {"advisory": "RHSA-2020:2117", "cpe": "cpe:/a:redhat:rhel_extras_other:7", "package": "podman-0:1.6.4-18.el7_8", "product_name": "Red Hat Enterprise Linux 7 Extras", "release_date": "2020-05-12T00:00:00Z"}, {"advisory": "RHSA-2020:2992", "cpe": "cpe:/a:redhat:openshift:3.11::el7", "package": "atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7", "product_name": "Red Hat OpenShift Container Platform 3.11", "release_date": "2020-07-27T00:00:00Z"}, {"advisory": "RHSA-2020:0697", "cpe": "cpe:/a:redhat:openshift:4.1::el8", "package": "skopeo-1:0.1.32-6.git1715c90.el8_0", "product_name": "Red Hat OpenShift Container Platform 4.1", "release_date": "2020-03-12T00:00:00Z"}, {"advisory": "RHSA-2020:1402", "cpe": "cpe:/a:redhat:openshift:4.2::el7", "package": "openshift4/ose-docker-builder:v4.2.28-202004061218", "product_name": "Red Hat OpenShift Container Platform 4.2", "release_date": "2020-04-14T00:00:00Z"}, {"advisory": "RHSA-2020:3167", "cpe": "cpe:/a:redhat:openshift:4.2::el7", "package": "openshift4/ose-openshift-controller-manager-rhel7:v4.2.34-202005252115", "product_name": "Red Hat OpenShift Container Platform 4.2", "release_date": "2020-07-28T00:00:00Z"}, {"advisory": "RHSA-2020:0689", "cpe": "cpe:/a:redhat:openshift:4.2::el8", "package": "skopeo-1:0.1.32-7.git1715c90.rhaos4.2.el8", "product_name": "Red Hat OpenShift Container Platform 4.2", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHSA-2020:2027", "cpe": "cpe:/a:redhat:openshift:4.2::el8", "package": "openshift-clients-0:4.2.32-202005020632.git.1.1b0fab9.el8", "product_name": "Red Hat OpenShift Container Platform 4.2", "release_date": "2020-05-13T00:00:00Z"}, {"advisory": "RHBA-2020:1255", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "cri-o-0:1.16.4-1.dev.rhaos4.3.git9238eee.el7", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-04-07T00:00:00Z"}, {"advisory": "RHSA-2020:0863", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift4/ose-cli:v4.3.7-202003161611", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-03-24T00:00:00Z"}, {"advisory": "RHSA-2020:0863", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift4/ose-cli-artifacts:v4.3.7-202003161611", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-03-24T00:00:00Z"}, {"advisory": "RHSA-2020:0863", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift4/ose-docker-builder:v4.3.7-202003161611", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-03-24T00:00:00Z"}, {"advisory": "RHSA-2020:0928", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift-clients-0:4.3.7-202003130552.git.0.6027a27.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-03-24T00:00:00Z"}, {"advisory": "RHSA-2020:0934", "cpe": "cpe:/a:redhat:openshift:4.3::el7", "package": "openshift4/ose-openshift-controller-manager-rhel7:v4.3.9-202003230345", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-04-01T00:00:00Z"}, {"advisory": "RHSA-2020:0679", "cpe": "cpe:/a:redhat:openshift:4.3::el8", "package": "skopeo-1:0.1.40-4.rhaos.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHSA-2020:1396", "cpe": "cpe:/a:redhat:openshift:4.3::el8", "package": "podman-0:1.6.4-10.rhaos4.3.el8", "product_name": "Red Hat OpenShift Container Platform 4.3", "release_date": "2020-04-14T00:00:00Z"}, {"advisory": "RHSA-2020:1937", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "cri-o-0:1.17.4-8.dev.rhaos4.4.git5f5c5e4.el7", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-05-04T00:00:00Z"}, {"advisory": "RHSA-2020:1940", "cpe": "cpe:/a:redhat:openshift:4.4::el7", "package": "openshift4/ose-cluster-policy-controller-rhel7:v4.4.0-202004261927", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-05-04T00:00:00Z"}, {"advisory": "RHSA-2020:2927", "cpe": "cpe:/a:redhat:openshift:4.4::el8", "package": "machine-config-daemon-0:4.4.0-202007092124.p0.git.2349.08d34d1.el8", "product_name": "Red Hat OpenShift Container Platform 4.4", "release_date": "2020-07-21T00:00:00Z"}, {"advisory": "RHSA-2020:2413", "cpe": "cpe:/a:redhat:openshift:4.5::el8", "package": "machine-config-daemon-0:4.5.0-202007012112.p0.git.2527.d12c3da.el8", "product_name": "Red Hat OpenShift Container Platform 4.5", "release_date": "2020-07-13T00:00:00Z"}], "bugzilla": {"description": "proglottis/gpgme: Use-after-free in GPGME bindings during container image pull", "id": "1795838", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1795838"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-416", "details": ["The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.", "A use-after-free vulnerability was found in the Go GPGME wrapper library, github.com/proglottis/gpgme. An attacker could use this flaw to crash or cause potential code execution in Go applications that use this library, under certain conditions, during GPG signature verification."], "name": "CVE-2020-8945", "package_state": [{"cpe": "cpe:/a:redhat:ansible_tower:3", "fix_state": "Not affected", "package_name": "openshift-clients", "product_name": "Red Hat Ansible Tower 3"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Will not fix", "package_name": "container-tools:1.0/buildah", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Out of support scope", "package_name": "container-tools:1.0/podman", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Out of support scope", "package_name": "container-tools:1.0/skopeo", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Will not fix", "package_name": "container-tools:2.0/buildah", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Affected", "package_name": "container-tools:2.0/podman", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Affected", "package_name": "container-tools:2.0/skopeo", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Will not fix", "package_name": "container-tools:rhel8/buildah", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Affected", "package_name": "container-tools:rhel8/podman", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Affected", "package_name": "container-tools:rhel8/skopeo", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/a:redhat:openshift:3.11", "fix_state": "Will not fix", "package_name": "cri-o", "product_name": "Red Hat OpenShift Container Platform 3.11"}, {"cpe": "cpe:/a:redhat:openshift:3.11", "fix_state": "Will not fix", "package_name": "podman", "product_name": "Red Hat OpenShift Container Platform 3.11"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Will not fix", "package_name": "openshift", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/ose-hyperkube", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/ose-hypershift", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Affected", "package_name": "openshift4/ose-machine-config-operator", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/ose-tests", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Will not fix", "package_name": "openshift-enterprise-node-container", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "template-service-broker-container", "product_name": "Red Hat OpenShift Container Platform 4"}], "public_date": "2020-01-16T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-8945\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-8945"], "statement": "OpenShift 3.11 consumes updates for podman from the RHEL-7 extras channel, hence why it has been marked as wontfix in this instance.", "threat_severity": "Moderate"}