RHSA-2023:1327MediumCVSS 5.3
Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products60
- Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:3a736c5d770150a34253a1cbd85f83289b7f57fb11de5fd5b54f60267e6b3767_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:663c387f7a558674ca164915bc062c5839d4aaab451c72b0728af1f4a2882f4a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:c3238f8f38f39733ee9308155936bbd7e574d52a2c1d150f4f2e6f8dd4a79ed6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:f0f6ea6af286b00e9fb570c63b372743e7c29c95651ec366696571ccfb29d9ba_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:1ef64b2a695bce10b05305512197e4745195234666b3d11f0da8c79ff3f039e9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:412681e1a87197f147d8e7e7cfa301c7ef955a9705771630153b084665270e36_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:97ec0abf03c44d68169f41a34508c2eb4dcdc078ff8e94aff2bf40f240397bc2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:ed640625bca8655222e155f9fb1565b550f10d0e19f586573be55a77cd4bc6d9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-capacity@sha256:085dc01d60a8577cf10c0989a15e35d9ab5d2e638c3ad7ad610878714050e567_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-capacity@sha256:414a036d98ad0843b3e57a9cbdc3a0240411debfaa623d3b3ad7b236d94fa140_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-capacity@sha256:c31f15f26263ca54360425c5bf5841f48ebabb1934a2dac99dfcc12163f2fca6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cluster-capacity@sha256:e6be71f0962bc11fdfa94b3347c7fad3139bd73be157d1904d8439cb3a324066_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:3b12700d1122a6948ae809696069dff8c2c016ff6e4aac3f77edcedc272b178f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:85e0e8b3a65d28382b61e690a86434eb89b09991f6c90495372797bfda62c2ea_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:93880f355d7a0b8d3ec686c280b755280a8469da066fdd9a705b1f118649b3fc_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:a72ab5a84ba0e7335ae9a19a8e2e5da46fb72799d79b512023d0d4caa3562416_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-dns-proxy@sha256:2432ded0869ad485b9f6566cad826b9b4f6c19a08394ce2b23680c04a793a17d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-dns-proxy@sha256:281de93b2a489597202ee862d4eebafaa66e1539c063b0dfe8cdc04b3b32d839_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-dns-proxy@sha256:6170b5b432ee402ffcea52cee9932209df94856d02e6d47063bc0a4e4b92b0e0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-dns-proxy@sha256:6b14a75f6ac58bcdb7b88fb3e21cd64826ca9ceda7b081d16d625780f62f221d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-http-proxy@sha256:7f3e96b390f1d73a0f8847c8464937dfe174b3417d1559625aec218b62c38ffc_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-http-proxy@sha256:b33839f05f1491340ed582ea0dfa3151515a1125dbaed27cfa108b3ffe95c4c9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-http-proxy@sha256:baccbaae5cc255249424e4665cbbe0abdf3d86c3e5055b7da15d948c34918482_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-http-proxy@sha256:e7d616464693e87eccef59b0029c4b951f7c04808e4df6c0f4885fdb981ee5d4_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-router@sha256:0432df3a9892a44d9970608f4127750f05909535298371e923367b538ed9664b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-router@sha256:5a76594c8af37e29c97f8144aff840a21c36a13916c4ec11945bd779a872b4d3_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-router@sha256:6d4f086579f5e15a28446e6b50ea21c1be984a396eacf21360f1ce0f0058bab1_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-egress-router@sha256:f44b1675aa5b06edc2c9f757f4bcbe4f67c52abab64da555c501c75ea087a6bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-helm-operator@sha256:389698831ac4bc85265f126e9b8ad8ff631589fdcd2914440460bcb9fd8e238f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +30 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html
🔗 References (38)
- selfhttps://access.redhat.com/errata/RHSA-2023:1327
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/OCPBUGS-10381
- externalhttps://issues.redhat.com/browse/OCPBUGS-10702
- externalhttps://issues.redhat.com/browse/OCPBUGS-10729
- externalhttps://issues.redhat.com/browse/OCPBUGS-10782
- externalhttps://issues.redhat.com/browse/OCPBUGS-10896
- externalhttps://issues.redhat.com/browse/OCPBUGS-11065
- externalhttps://issues.redhat.com/browse/OCPBUGS-3057
- externalhttps://issues.redhat.com/browse/OCPBUGS-3624
- externalhttps://issues.redhat.com/browse/OCPBUGS-3671
- externalhttps://issues.redhat.com/browse/OCPBUGS-3679
- externalhttps://issues.redhat.com/browse/OCPBUGS-3682
- externalhttps://issues.redhat.com/browse/OCPBUGS-3683
- externalhttps://issues.redhat.com/browse/OCPBUGS-3689
- externalhttps://issues.redhat.com/browse/OCPBUGS-3707
- externalhttps://issues.redhat.com/browse/OCPBUGS-3745
- externalhttps://issues.redhat.com/browse/OCPBUGS-3747
- externalhttps://issues.redhat.com/browse/OCPBUGS-3815
- externalhttps://issues.redhat.com/browse/OCPBUGS-3838
- externalhttps://issues.redhat.com/browse/OCPBUGS-3906
- externalhttps://issues.redhat.com/browse/OCPBUGS-396
- externalhttps://issues.redhat.com/browse/OCPBUGS-4066
- externalhttps://issues.redhat.com/browse/OCPBUGS-4346
- externalhttps://issues.redhat.com/browse/OCPBUGS-4462
- externalhttps://issues.redhat.com/browse/OCPBUGS-4722
- externalhttps://issues.redhat.com/browse/OCPBUGS-5178
- externalhttps://issues.redhat.com/browse/OCPBUGS-5293
- externalhttps://issues.redhat.com/browse/OCPBUGS-5377
- externalhttps://issues.redhat.com/browse/OCPBUGS-5822
- externalhttps://issues.redhat.com/browse/OCPBUGS-6184
- externalhttps://issues.redhat.com/browse/OCPBUGS-701
- externalhttps://issues.redhat.com/browse/OCPBUGS-7826
- externalhttps://issues.redhat.com/browse/OCPBUGS-7856
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1327.json