RHSA-2023:4341MediumCVSS 7.5
Red Hat Security Advisory: Logging Subsystem 5.7.4 - Red Hat OpenShift bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-25883 — nodejs-semver: Regular expression denial of service CVE-2023-22796 — rubygem-activesupport: Regular Expression Denial of Service
🎯 Affected products64
- RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-operator-bundle@sha256:e56a09fc05288a5a2ef9eb4ed9536b517e5a19b6317be07ac9caeed7cdabc2c3_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:49c4aebcd64396039f8e6d6cce6c55a92d6bbf6108ddf72bdc53606e26ac2b4a_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:67ef8c821c9b3bca057ea7199aef6e911cd7f7f999ddc2fdf82c8075794b0aa3_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:c65f10b5e11fd2310b21c4acbd56d1fed311e0dd69f7c33d6b2fa0e83bf2d64f_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:e0c2fee54eac82bb2db9458c66f5989d1ece106028facc0bf7630cdb10ce22d9_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-operator-bundle@sha256:907c78f7ca1b56bb2ddc79b5b5555c39fd061190aebe72862bbd672c94b248b0_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:8ff461c5c4c305e1ae2991bc5df6dbf98a51b0ecc4bace6706f574beea7f64dd_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:bb1a983e04d731a4e580cc0eff4216951ddc8a9eb27ed14b1960f2b434f3cd2e_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:cf018227104330f7930731e0807ae6e4e877890bb3ab9e6d726a6765c9609a06_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:d4baa438f24a85b8be45f0bd121d738af1503ebf18e2c54d655acb6cad9e50cc_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:44ba718456214efb36904719c4843c82449ccb18696925c7571324b4eb4a1c4c_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:5575edf75617e0bd07aa97490cffd26f076aa0bcd82c3274538ab45d51e00225_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:bd46b16c0677fab4a383572c274edebbc69c571045ad449d3b5d421405f5672d_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:c2571e820b058d0b2baaa952a3c841646e777d7735561b1a43e1024ce606ff9a_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:4fdca7719007c06b5b749a4c89f80f6c9056150f9e60e00933c2c0ee1b7b6441_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:7af0fa05193b2f75a270c16355bcce6d2117183d59f5ed4d040d5a8e7d40e610_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:df161e83a11d953b4867faad7079fed1eead2e8fc727902b7ff9671f8d4b1c5d_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:f2d5044bc2af0ec3e78732ae8785d217e80ff18332fca0629ca06c7d481a0d9a_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:0f91fc53a5053e39de0fe264281a56a179a2b78718cfadec1e1b29506630ab70_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:34ce66194dfa6a7a20185095f0766ad57fc61225c080b67e558a81a81f815724_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:3df6df351b2f6da84340867d2895db147313931f8d82479b8872da64bec6666a_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:f28aecb4013c43132d6261fd6817a65c2237dd8b5d9177999277ede0a228c79a_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:1683bf2947833563d426e07b078e14984ea9c4f2a6da2931979eba3277f6aa2a_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:337ee7e9da6cc5eeb19f5f2d626c264f02e4d928fc0966943da66e1feb3d9a7a_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:9a6c4ab015df408ff848234705bf0fbff5332e85279485d2b758f23156a9c572_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:b6c6af01832e14bbfa3077448ee626daae770e1366efdc0f0784498f4d30e6b1_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:403c0dd709adab3bc11330a6939e587dea1739cd5670965467f4760530f8df48_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:7123433d58b6579455cc263f19c85b63ea951d89f66e2b733bac98a9b7ceac4b_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:84fb35d90e834c43f5159b21140c8b94c21ea9124449425596799f80c7cd8020_arm64 as a component of RHOL 5.7 for RHEL 8
- +34 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2023:4341
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164736
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216475
- externalhttps://issues.redhat.com/browse/LOG-2701
- externalhttps://issues.redhat.com/browse/LOG-3880
- externalhttps://issues.redhat.com/browse/LOG-4015
- externalhttps://issues.redhat.com/browse/LOG-4073
- externalhttps://issues.redhat.com/browse/LOG-4237
- externalhttps://issues.redhat.com/browse/LOG-4242
- externalhttps://issues.redhat.com/browse/LOG-4275
- externalhttps://issues.redhat.com/browse/LOG-4302
- externalhttps://issues.redhat.com/browse/LOG-4361
- externalhttps://issues.redhat.com/browse/LOG-4368
- externalhttps://issues.redhat.com/browse/LOG-4389
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4341.json