Red Hat Enhancement Advisory: Red Hat 3scale API Management 2.13.7 Release - Container Images
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products33
- Red Hat 3Scale 2.13
- 3scale-amp2/3scale-auth-wasm-rhel8@sha256:6482676ba77f470ff671ac523674e86a609cfa064b59edeba84f5431423fba8d_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-auth-wasm-rhel8@sha256:a3641417e69305f6aaffe22459879e0c550eabd5d814d19896a417a1aabb4c9f_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-rhel7-operator-metadata@sha256:352ab243649889842cf0f326cd4fce1868cfa57eb544f553eea8a6cdd6cb4d3e_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-rhel7-operator-metadata@sha256:7640944214f9431f5783368d7c9a5a25fcb1b1c897755c07872138a5bf5ec6f7_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-rhel7-operator-metadata@sha256:7f09c8239d22e839a201e2baa598ded32f15f66b2736d51159c4c3710d34b472_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-rhel7-operator@sha256:bde9ba77661146621d353e6d0827060292c72b8542ae8fd5d3790411a823c639_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-rhel7-operator@sha256:cb57b7338561b5e2c18759726847e33a164f95440b9e5682654638297d5c5f69_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/3scale-rhel7-operator@sha256:f4508a6fffd3e604942e0e12239707e05cc5657765c100fb9953f0405206fd39_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-gateway-rhel8@sha256:8b98559a9d68b7169664db60c8e492cdf3319771bcffafbd50468e93cfef9cfe_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-gateway-rhel8@sha256:c352f6912a4e54bfe725360994674b4ce8a815777db7d3554b6634e341d1ed5a_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-gateway-rhel8@sha256:d8cc91c649553c49e0da15f7ab7466be2e78ef3e00c2a7b743f69c1891b75dd5_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-rhel7-operator-metadata@sha256:6da016547c24d2c1e044ae8f6639da6a2975792583501d4fd7d9839935941739_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-rhel7-operator-metadata@sha256:868ecb3ffa5a83b3eda3f7f4ba31dad0e57e97b857b657a46c8bbdfa69a27922_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-rhel7-operator-metadata@sha256:cb9e6381aa2b748a0ca7d6a90de784bfded5a57e0446df6b217b9b5112dfa9bc_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-rhel7-operator@sha256:4975248f24d7a5bb414729f66d98957cdac23cabefb1b6b8b60bc50d5e4a4ec7_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-rhel7-operator@sha256:89b3c616730f3d88082e44fd9008c8c58dc85f7e3e55cf6817efc406e37fd861_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/apicast-rhel7-operator@sha256:f6b3e65a3acfdd12f3c091deecd95b86932ad1a0174d303a05fecca54c1cbc70_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/backend-rhel8@sha256:081ef7a49e91fd6a88a89e3d5c61f47f59658a3688635dc9680e7182f5af74c5_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/backend-rhel8@sha256:3f67636d93ed7e1a5fd0ae3a9bc41e0ca4b80180d40638ffc9fc11e682740bfc_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/backend-rhel8@sha256:e18b80f1a9a2282f7073c91c4f17fb4e24aa4cf95dd17fe384f61fd844a0f48b_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/memcached-rhel7@sha256:92320cd96dfb3e5279825f6a019c8c3c6d365252474dc4fe1ec9196d7e9d579f_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/memcached-rhel7@sha256:e42b92c87ce020174445ebb0d506dfff90da15c6710a2a1a046a61ad39052b90_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/memcached-rhel7@sha256:e66fe95ce5d29279dba41959c86a6c1c19d6e69cc4198bb1a6c994fbab47b009_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/system-rhel7@sha256:18bdf176bc553ddf16c6738159c57b78b081ab646a051c130814cc84fcb3367f_amd64 as a component of Red Hat 3Scale 2.13
- 3scale-amp2/system-rhel7@sha256:e1ac0bd8d5178e30712cb9a1e88874a8c2093d562fa44bbf80ec131ae30a4e71_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/system-rhel7@sha256:f42d5705204ffbdbd3d72764d3a69008cad4b2384d630a44d5f700cdbba24a88_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/toolbox-rhel8@sha256:31b55a31c944120649adef59b3ed41ebb252acff454fafe9dd5bf5990abf7d1b_ppc64le as a component of Red Hat 3Scale 2.13
- 3scale-amp2/toolbox-rhel8@sha256:480e758bf61a1c77545daa8d078bf1f26ccfd5153723ea6e1159e61e5f11a5d0_s390x as a component of Red Hat 3Scale 2.13
- 3scale-amp2/toolbox-rhel8@sha256:4c3dc23845a2a2a4428e1d3c92f8154d6af74a4cd3b85770c7de41dc6cfe8432_amd64 as a component of Red Hat 3Scale 2.13
- +3 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_3scale_api_management/2.13/html-single/installing_3scale/index Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.