RHSA-2023:3495MediumCVSS 7.5
Red Hat Security Advisory: Logging Subsystem 5.7.2 - Red Hat OpenShift security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-27539 — rubygem-rack: denial of service in header parsing CVE-2023-28120 — rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
🎯 Affected products64
- RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-operator-bundle@sha256:67922a4fa417673d97eca28344c77ba81d4f77cb1b86e1ca532b41a82b6f6520_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:60f75c6ae180291f7e8eae0dd9999f0c17a74863b20d23f45a675cb427cabcf8_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:8619dafc0e4d978c2eb63e0dbb0389114bbf93c692dc1477ed776c40e589c677_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:ae56b7bb5f88e54739e103c16b57eb776661c8942d0d58dae683f33dc839191a_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:c127a5211070607bc6daaa404fb221a91134ee18261691041448fb18203e711b_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-operator-bundle@sha256:f56e69a40c6f51da46fbaf3fd170f84e20a45bac6c77b3b6d16130ae7be62394_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:0abd84da4fd5bf4f2657c0a7ba2f8fd8b878c15121fccbe8fb5f461b2ea5a9b3_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:160985f4c009f8cce7b36c1142756f25ff2413937da194facc6bc85cb0863551_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:22a97db8a595aaa758027b30c7fd2cf3ea0ae6c4d0b70766f8124d8eb17b58c9_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:38404132fe318e05f607c0e0ffb78baa25bb9477f53f40436b0cc50d21dd52bb_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:5aaa60e772fd3f47d7b12d12c2eb55176803175656f834c48ed5003bf6c80600_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:61c30851d3d9f544c37c7616ec8a4ba34b7b37f3555960d0c8fa2be78f44947f_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:ab54ef61832141f7675d3dc8d59edf99c3cdd1125c74e222492949c180964452_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:fa36283092c27cd60761703d1eee07b92358dfe1157273b51b37b583a6060b35_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:4685b2792af31c22d64220aaf7693e121826fdc2d8acd5be7bd0557995b8dea0_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:611cef3b88e71c24f002e3a37de6883f54ca0e8eb9f8b60aff41ab2dcb249745_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:9c28c1ef4a26ab31a9de8941b22705cea8e85918df5e9997cd07ede5bd04e512_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:cc65e3adf0590cd58a073f351be36a2bc60ea1aa0183a0c9dcb9ae726830a078_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:05c5123b3c5757f6239327c7ee96d2ce9fecbeef1dc39feade38d9417941122d_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:62134203e3d02a92b4ea0f0f6b96a4046806c655f9b8358de7576a57624a7574_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:9a9fc94b921453a383a8e2503bb8ff4e1d5290a541d5819ea15b263f10589357_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:f8ff9fda083e55a5113ba614c739d83d52ee3115429075d0eb03fea2e9d5d711_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:3d3d4d46d57443ea5aea72a711126ff46b217129f089864f027b1ed2b45e393c_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:5dd0468121013d75c3c5b5def726b6d71f66d2086defad6cc1d54015f057f956_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:9e35721ad22c9c67e6bd49f7978c495d72743ad43c21425cb97a57b5f6d03653_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:c082515ff5bcaaf305b24d24b488b2d91627894872b2f2074f7bfa64e0baf313_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:77a3146e462f9291ea13d13fea97c74b2d59fe84f3dbfc33aafc08837fe5baba_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:be0b14bae5a4e42bb760ef93676153d2e9d0eaa72075b745df29ab519223a226_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:c8dff12b758f72cb6096c83a9b0e4918efab24e41c60e3dd1db91b561a204a9f_ppc64le as a component of RHOL 5.7 for RHEL 8
- +34 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Setting Regexp.timeout in Ruby 3.2 is a possible workaround. Workaround: Avoid calling bytesplice on a SafeBuffer (html_safe) string with untrusted user input.
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2023:3495
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179637
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179649
- externalhttps://issues.redhat.com/browse/LOG-3314
- externalhttps://issues.redhat.com/browse/LOG-3316
- externalhttps://issues.redhat.com/browse/LOG-3330
- externalhttps://issues.redhat.com/browse/LOG-3445
- externalhttps://issues.redhat.com/browse/LOG-3749
- externalhttps://issues.redhat.com/browse/LOG-3784
- externalhttps://issues.redhat.com/browse/LOG-3827
- externalhttps://issues.redhat.com/browse/LOG-3878
- externalhttps://issues.redhat.com/browse/LOG-3945
- externalhttps://issues.redhat.com/browse/LOG-3997
- externalhttps://issues.redhat.com/browse/LOG-4011
- externalhttps://issues.redhat.com/browse/LOG-4019
- externalhttps://issues.redhat.com/browse/LOG-4027
- externalhttps://issues.redhat.com/browse/LOG-4049
- externalhttps://issues.redhat.com/browse/LOG-4052
- externalhttps://issues.redhat.com/browse/LOG-4098
- externalhttps://issues.redhat.com/browse/LOG-4151
- externalhttps://issues.redhat.com/browse/LOG-4163
- externalhttps://issues.redhat.com/browse/LOG-4185
- externalhttps://issues.redhat.com/browse/LOG-4218
- externalhttps://issues.redhat.com/browse/LOG-4219
- externalhttps://issues.redhat.com/browse/LOG-4220
- externalhttps://issues.redhat.com/browse/LOG-4221
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3495.json