RHSA-2023:3367HighCVSS 9.8

Red Hat Security Advisory: OpenShift Container Platform 4.13.2 bug fix and security update

Published
June 7, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24536 — golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption CVE-2023-24537 — golang: go/parser: Infinite loop in parsing CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:9a021bcfd3e45436caa5621f4363976539fd857cdb447ae27fd717c64271ed25_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:b9ec0fce13612e6065d8a3e5b5d65ccb4e5c7c05b14578dc0ca2cfcaf9550045_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:bf697e678e3add063caeb2a6936865c000aad24a3deb6a62a21f91e343c1539b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/cloud-network-config-controller-rhel8@sha256:c18c644868144caf57ef17c922bd522de342d9106d447261072f270872565f84_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:595afb7c33d7fac4b7cabc00bd4167b4d615410858a0bf0383500ac537c08a4b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:8e141364dc2060b5101a03fd5b97ccd570ec223076e409e4f6277c986b915ff3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:c17efac026ff7d3b0288fef3d074f6073511d60f90cd4f93a3d4d87a0fd99f3b_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/driver-toolkit-rhel9@sha256:d1261b7301bdbbc1c1d518b44ebd5329048dcd5b6aa44baa85e4886346e7272b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:0b7d0678f9d4fdbf81c58735fcc2dc4cfb1ffad6cc9bb3c7514165d2d4269709_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:0c02de02d3f09f71e07d646227e17d75512d610c3e618db93ebf76e030ef9928_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:5700222139d8e96585df089bb569100302c26c9e4feabe33ceabef941b00ca2a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/egress-router-cni-rhel8@sha256:d6a825782c72887c79e56f964c11b4b450ff9cc4f89641170d113dd5ff61ae42_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:0dfebff85cfecc48af4b7d6794fbe6fd68be57c11a568866c207308b88688f41_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:4b3eb252040747ee2f7938a38db43517c379c57cab8c6b96a65a46f6742fcb36_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:6c60782a1d9af2be1ae772cf543394ddaa49128dc9449060fd9bd64592741fda_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/kubevirt-csi-driver-rhel8@sha256:8e1935250001e2f0271a23b844eb99e765491c0cb18e86a084a844c7d08a5a18_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:2e73cab4e9d2f7a45191c5656686583a8ea2bb8517f9f73f40928fba0ea48103_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:44d168048cff5516ef48cdd49834b44765a1a644d81d15d832164e9a67c122a8_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:99c87b771b66d04d999ed516fdad724b2fd3ac07840b5d7ae4b0558a7f23b420_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/network-tools-rhel8@sha256:bded9a0ff7569715fb07d2bff4798e90a6249da76c967192b82a00ac0d42699d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/oc-mirror-plugin-rhel8@sha256:8d2070878cdc2d555de5b7721bc15547626e77746123a4ab1f8397fe69eb4444_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:3b95642e74cd68877f8a8892bb4a564836caaff3b6d12caabc4068002a0d55d9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:5753228cb1acc9385dcdc0b5ebf5ffcb739b96901381d905f6e35a74b96680b2_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:eb9a7d59b65e46cf04294174d8a92fe15922cfbe9af7bfd4fe7a3e243d464da0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/openshift-route-controller-manager-rhel8@sha256:f274ced3b66514ec92846b7a1984789b2425ddf9add8c282db709d3beb1f1b91_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:50aae8cf9e4d3da0ec28afb8d29e453390cf5544b1f1a6eca412e190347ba4b5_s390x as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:b8facadd266df2aef089b1ea27fbc1196e36b29b23f1aeeaceaa9109712af0ee_arm64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:e92d5ec242ad90a1c63b5caae7e97afc5991380989f9cbc3c5b515ce4ae6cbca_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:f8e7aad960ddc3ce2e3857b613531b2b2211641496e964f0631f3bdd3916983a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:6ef3cf4bed1970d547dce08a6e334b675d361b212427c4493151dcad6e093d27 (For s390x architecture) The image digest is sha256:a600147c885c1a5472552ca388727ad1276f0151f8d0ab6ef3e9e957e839ad23 (For ppc64le architecture) The image digest is sha256:6d0a80ddc826ecef0369bc8ba5bb03c84b5ffdad9439ed27e5484280161b0708 (For aarch64 architecture) The image digest is sha256:3cf7068c1c6a5a6e1195e6c9658b1e1093dbcc0af7e1de6eaf446e79af83c1ce All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, upgrade Go to version 1.19.8, 1.20.3, or later, where the vulnerability has been addressed. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (24)