Red Hat Security Advisory: Red Hat Ceph Storage 6.1 Container security and bug fix update
🔗 CVE IDs covered (35)
📋 Description
CVE-2021-42581 — ramda: prototype poisoning CVE-2022-1650 — eventsource: Exposure of Sensitive Information CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-21680 — marked: regular expression block.def may lead Denial of Service CVE-2022-21681 — marked: regular expression inline.reflinkSearch may lead Denial of Service CVE-2022-23498 — grafana: Use of Cache Containing Sensitive Information CVE-2022-24675 — golang: encoding/pem: fix stack overflow in Decode CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-26148 — grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-28131 — golang: encoding/xml: stack exhaustion in Decoder.Skip CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar CVE-2022-29526 — golang: syscall: faccessat checks wrong group CVE-2022-30629 — golang: crypto/tls: session tickets lack random ticket_age_add CVE-2022-30630 — golang: io/fs: stack exhaustion in Glob CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-30632 — golang: path/filepath: stack exhaustion in Glob CVE-2022-30633 — golang: encoding/xml: stack exhaustion in Unmarshal CVE-2022-30635 — golang: encoding/gob: stack exhaustion in Decoder.Decode CVE-2022-31097 — grafana: stored XSS vulnerability CVE-2022-31107 — grafana: OAuth account takeover CVE-2022-31123 — grafana: plugin signature bypass CVE-2022-31130 — grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins CVE-2022-32148 — golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-35957 — grafana: Escalation from admin to server admin when auth proxy is used CVE-2022-39201 — grafana: Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins CVE-2022-39229 — grafana: using email as a username can block other users from signing in CVE-2022-39306 — grafana: email addresses and usernames cannot be trusted CVE-2022-39307 — grafana: User enumeration via forget password CVE-2022-39324 — grafana: Spoofing of the originalUrl parameter of snapshots CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2022-41912 — crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements
🎯 Affected products19
- Red Hat Ceph Storage 6.1 Tools
- rhceph/keepalived-rhel9@sha256:2ae4274163155d880cbd41d1a197d6856f326501a50e028ff3de9ff8a85b3e97_s390x as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/keepalived-rhel9@sha256:36abd2b22ebabea813c5afde35b0b80a200056f811267e89f0270da9155b1a22_ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/keepalived-rhel9@sha256:b21d882fd2d08d6f162dbb63e0626d9d6aa892a677c5a28edc97b84feef1655a_amd64 as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-6-dashboard-rhel9@sha256:1d7ca201b778e6a6cb559129e240233b6b6461399c67f979c07d5fe288c400f6_amd64 as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-6-dashboard-rhel9@sha256:3fb7480f9d68333e168eae0c9fbeceb0df7962a40c25ecced81ea4c4959b2c25_s390x as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-6-dashboard-rhel9@sha256:50329da263e8ef00c47632156761621bac30fead5e574ef23cd1d30b7af0019a_ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-6-rhel9@sha256:72bd6eb932a368af10d5c607d8b60e0fe8b87862f4adaa17fd022a3427a46ca8_s390x as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-6-rhel9@sha256:953630d9f9924f17ab7ce168772c3facbaf6866b79a1cf0fb9aee1dcf6eb8c7d_amd64 as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-6-rhel9@sha256:9b477366f861df49b533d95941b9770b032827bb4a259c5f86abce8705960c05_ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:720b3207087d4feb8ab59ffd0b70d6bc22fa21d53b62393779dfaf8972a32e60_amd64 as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:8cc4a146d7be5046b416fe9c04d77b4f0a25a2ab7180fdbf8c46cff8e2483080_ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-haproxy-rhel9@sha256:e4da2c9d53159d43c6795151eb3c9dea373da19b34d76094b60e7a2466415d62_s390x as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:44697ad0d15d1f37b98243f5f013cb9271d70e2b10ab52093a1d7e3409a674b2_s390x as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:b46c0196fab3bd3a60b64a1d7ff8af6fbc7c3e526618da1cc78032bffa3be171_amd64 as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/rhceph-promtail-rhel9@sha256:f52fd8d5fbfdcc202c5e31096119377a8b87f9efd31602398d45cec86ec35940_ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:8887234fbbaddf620eaa7b0f4b1ed6ab8aa5bc52e019e67179554ccd03fba676_ppc64le as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:9078b49846d8ec681bec5b96f0d4087b4c66bdc6baf4701cfc9c8e8aeae89661_amd64 as a component of Red Hat Ceph Storage 6.1 Tools
- rhceph/snmp-notifier-rhel9@sha256:df7c89608fe8352d445efcc1017521b35878cfe61a8b9fd91fab24c00786b2bf_s390x as a component of Red Hat Ceph Storage 6.1 Tools
✅ Remediation
For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) Workaround: To mitigate the vulnerability, disable the data source query caching for all data sources. Workaround: Sanitize the user-provided locale name before passing it to Moment.js. Workaround: Disable Unified alerting. https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#unified_alerting Workaround: As a workaround, it is possible to disable any OAuth login or ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (42)
- selfhttps://access.redhat.com/errata/RHSA-2023:3642
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6.1/html/release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066563
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077688
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082705
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083778
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2085307
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2104365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2104367
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107371
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107390
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107392
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2125514
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2131146
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2131147
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2131148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2131149
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2138014
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2138015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2148252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2149181
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168965
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2174462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186142
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3642.json