RHSA-2023:0932MediumCVSS 7.5
Red Hat Security Advisory: Logging Subsystem 5.6.3 - Red Hat OpenShift
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-24999 — express: "qs" prototype poisoning causes the hang of the node process CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products64
- RHOL 5.6 for RHEL 8
- openshift-logging/cluster-logging-operator-bundle@sha256:c45854097cbbc184830cc41e57518afd1d93b909c5a6bf62d17cd922460f05a2_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:0e167d232bdccdf71846b69631314df97660da3e3581a9a50d78a85925b47883_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:25e99a1b6236720d27af67885dc9977c5a57ed7223ee26e00f97a6c77697fd38_arm64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:911b3a6a531023ec51a42aad73cb56c5710344568226eada7b7332f51bca4167_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:d740ec313b251b04c2fda54b810617d0d61c586598a72a1fff2c39b5ff2b2a23_ppc64le as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-operator-bundle@sha256:071423618c82b05abb31a7697b1b0f53cf1f6174a4adcc673fd7e080a2353c2e_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:00995f237bb8d4ec4fbb7643225a6ba191894f98a269daffba942e5aa1226f73_ppc64le as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:0ef99a61c41e5ba3f013ee8c3cbe3c9455f9089140f0685af4e551fc411dc1d4_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:a799a967668e9f45f31be3ee65f2ae6e61fe6dc0b583606f9c57b54c460bb1b6_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:e6d6352ce2ac7178ca7730294f3dc6a2f6f6f85888e52c3621722c548dea09f9_arm64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:1a4555f082a0d0cb9de7b2f6ceade4201917c68949b96cd34242f60ac6b0e452_arm64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:5a654a50c82878518a0ff57cb63b0a7edb4c3019d25dd54bc99cc1c9b842722a_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:5f02319bf9745be1aacfee77cdefc47ff54e7567e89dba56c07b1e17e4447e8e_ppc64le as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:f6395b5342fccec8414c71e49a7b8b3a0cdc6238abce4bcef97268f1fdf510ed_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:c03b5d752fd169db97532eac64c10871b865fc351536f2b4c471165534c2bf59_ppc64le as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:c5f20bed7139363cc8c12fb3d38341027d3660ca1d8d1b3a74b6a2eb0d753ba9_arm64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:d9a3af8383fde0e7e08c8cd6a6679507d621900fc693bd5ed432234fb9184ef2_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:f90bbb41cab58931aab34890b507d5fa2c2ae08b6320d4b35bd367f5dabd8f50_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:2da4527aa8d97669d602c7cf94373e16ee0dc2851e2303de49a919c3a85e1f41_ppc64le as a component of RHOL 5.6 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:50aae19f0750c0f35a905d81a758ff2c9dac6e410a3c6c0b76f9ef8ca112a64f_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:e59f049fac9cdbcdb695efc84d014fee9ed6d13c64ec2e8818fd619aa14dbe1d_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:f861fadfefcf3e81597a33e94285603ea45e1956eb558279cee9a128012d0f59_arm64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:5c97c94c0904b478fe8b13a5d8127c053859046105a0baf4807700c2234998d9_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:933a3bf79972f2e5c8ba21aac1584778528dc6d090c1269fb9eb7f98bc3748e1_arm64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:eb1994e66ed00564f8dfddcb7b6b3276ef4eaa798099c61b7eea6c803e329e35_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:f6b065eded5ec8c80c22a49ca37453dca681f74f8851490a178d813c77f27d62_ppc64le as a component of RHOL 5.6 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:344d9cd561f7c62c6de21d2bac7662827edd530239e5607fa1eb6d1f8ceefdea_amd64 as a component of RHOL 5.6 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:600e20533b2bb2f67277a19c1fc3a0732da6f01afd01e1b552535669ff88c262_s390x as a component of RHOL 5.6 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:7599a21ef8a5f6867cfc3f9a2a4126847b10060480469a6b91882b97905b0cad_arm64 as a component of RHOL 5.6 for RHEL 8
- +34 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:0932
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150323
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/LOG-3717
- externalhttps://issues.redhat.com/browse/LOG-3729
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0932.json