RHSA-2023:1310MediumCVSS 5.3
Red Hat Security Advisory: Logging Subsystem for Red Hat OpenShift - 5.5.9 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products64
- RHOL 5.5 for RHEL 8
- openshift-logging/cluster-logging-operator-bundle@sha256:9f60f36c29ff954106e3966d1ca45caf1a10f25047f3888a720514bf762869fb_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:0a0559da7e9e6ca7de48c93f08e0930b187d0da1294d077c5340dc08baf3765e_ppc64le as a component of RHOL 5.5 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:10d3c60fd3c4711ce52b90a4e05dbeba807932d496ffb15ec9dcf0a88955de7c_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:83ab545bdf779f8ce4f50604ee4a626fd6245d31ae83a612438970d9a743321d_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:af8c4c2299729cf48c54fc9b653c354a08cb116e516686e16644fdd68d58fdac_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-operator-bundle@sha256:fbb0b82e4e102301e87500dda886861e39983eff3511cb8b7c957b67732e8e6a_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:22aeaaee7f95e69f14732084758be53e37734a65a1c02dd05143d56654167968_ppc64le as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:44ed5004550c6d15e054e9367467847e13ae413d6a2e36b6c67842032456f95f_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:ca144406aa4d66149d9c530f245c11eb753b0a20a2f09411202b19f238d474ae_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:db771f2b0b292131caf29b0c3e646559a8aac0cc6b42bf5c0fe3e2c10721edfb_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:05b7944bc2f51fe3a19420d3a0d42b6944fa7dc4fd16860557aae97e81972093_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:29172efc78a450b37d3e549abd4f152aa5974e86055505617479fd8517c54077_ppc64le as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:99adbffcd95fa7b6e0a699a3687f47cefd95815552c78ea44359898c1ef5a11b_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:cafbd320c49ed0c24453ece94d05bfb7c20a5c54cd735f89b1f1595847fd6f2c_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:01fea4b904e5081994feca65f14a113bee7402e6f9e32c86de56d78892069248_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:51f06807e4bbd2f7e67d51405e211969a36f5c269b8e29a5f31f906affc0bee9_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:9bb68ee00ea4bf7897bf785dcc5a8f49f77591b2c520a0499b9d593f1f7f3e77_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:afa21e9a6daade99d696bb3ff311fc563fe3b6d4cc5394db5bca99b8461b30dc_ppc64le as a component of RHOL 5.5 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:1812310845beec68f17c1d5f62180c21ae33cb6a8d136df2b04847281cc4a550_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:abc73d7c56ac041fb666c0fcd954cbdd5bb1e7f5574ae8f44d110d9464d63e53_ppc64le as a component of RHOL 5.5 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:d09004093fa414f69702473c1f4b8776c9245675e6754186d7a0cacf55c0a9f6_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:e51150b8d08b80036d68631f9fc91e9da331725d58c65699090c5dd0d7f338e5_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:0d36a99eb193d94f446b1403c4a32c138b6ccf10771a2c5f879a4fc8d7e248fd_amd64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:158218c517e6829dbd542ad4bc8d9b2697db1a72d5bc6507621210e49ee3c08f_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:7ba453711bbfa2bde1ab759d77eef773fa7bda16d4dc5e305025175d1ff96edc_ppc64le as a component of RHOL 5.5 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:f463acdf2d2ed9b5674df0ba079c2f8be65f761bdc3781a2ff49f323bcb690d0_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:10722dc15493513ac834200593930eb93a6b231a16365dd92e5b117570a472f7_s390x as a component of RHOL 5.5 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:3e52d684d044b03e33f47de2a2dffdf9543ab69d02c7a24a71a53b980ae1a623_arm64 as a component of RHOL 5.5 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:969c90a986d2b6d9f24957ef1e095e4e40bd966781636312f0d543c20be8680f_amd64 as a component of RHOL 5.5 for RHEL 8
- +34 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:1310
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/LOG-3730
- externalhttps://issues.redhat.com/browse/LOG-3767
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1310.json