RHSA-2023:5006HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.0 bug fix and security update

Published
October 31, 2023
Last Modified
August 24, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2018-17419 — dns: Denial of Service (DoS) CVE-2021-4294 — osin: manipulation of the argument secret leads to observable timing discrepancy CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-36157 — cortex: Grafana Cortex directory traversal CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2022-23525 — helm: Denial of service through through repository index file CVE-2022-23526 — helm: Denial of service through schema file CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-0475 — go-getter: go-getter vulnerable to denial of service via malicious compressed archive CVE-2023-0620 — vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File CVE-2023-0665 — hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-5408 — OpenShift: modification of node role labels CVE-2023-25000 — hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations CVE-2023-25165 — helm: getHostByName Function Information Disclosure CVE-2023-25173 — containerd: Supplementary groups are not set up properly CVE-2023-26115 — word-wrap: ReDoS CVE-2023-26136 — tough-cookie: prototype pollution in cookie memstore CVE-2023-27561 — runc: volume mount race condition (regression of CVE-2019-19921) CVE-2023-29401 — golang-github-gin-gonic-gin: Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:2754f299655dd2602edad61dfa91304ae1c0029572a415b03fc1ac3d370bfe94_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:966d449e7adbeb1e544e098cdd1e9da038d06008c66991f7428b04b7822f5306_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:ee4206f5dd2ec1131b5d3767eecbe406d367eecdd64c855dac342c062d7746e0_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-network-config-controller-rhel8@sha256:f411ce6d45d11e777056b419207d13c25f7f1aef1d48db16661a75d2847387e5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:377b5ecf886c5c480252bc5b705816e5b87099c33166af1ebb2ae6d349b204b9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:4688e606084d786173625273c0eec61feecdff462152c89e270122965f5dbd03_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:aa148ddc6652edcef16251250e7d4109f4fa4021a679b25afac68afe4be96ed4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:af67382cc919626aeb7c97fc7b8417eb5ea693e0a045012bb9505fd0d25453de_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:1f944f82114bd4b6e1ab644602fcd88d9eb8ab8602c19a55209e09167439c050_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:37423ddf95089d0890f7d814d6255ee4868981840bd7c342e2bea9fccc600e04_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:4a47ce5f3aed2776d020ca37f3d204d1e9a6521bbcd814122940dc546045b174_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/egress-router-cni-rhel8@sha256:c09563b276d74a777477ffd84fbad9a6f5a5f199970860686ef1a192bd27f0f1_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:0e47748346641b0570f20638322a25965c2363b9dc8ff4abe516fee50cc2700a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:88a3b999470a6665ba5de0b89c6c98b8eec8bf007b7d54a188f851b89b646ca0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:b213ccd2c047d673b48df68824de5af0eab5eda60f2ca20f6997b28e0e3fb7ee_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubevirt-csi-driver-rhel8@sha256:cef9c75ec6447eb7d783bf3cbef1c35ed301d52fcc05d07f1ab30e358f3c6a66_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:12c078944f882357045db638f547762dc642a7b3f44531c74cc062219b2611a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:2fb0665feeac5d7271f494850d37497efdcfc872cf034c30229d585dbea29a0f_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:41c4193c89827d4819f273ed1d7a1f705fc6a9c8a1bd7f613e50a8551eee3fa1_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/network-tools-rhel8@sha256:fc2d063f282ae6294a9945152610a621ed67aac9ef6f31d9fa2299f382e6e8bb_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:17212365032dffa6ca4b840b7da03556f5507970fe28c68398d2fa9f4f0021ea_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:3057b1f2dd57dc0b60e96e30d1cbf09e5f5bb9c701fdcd00c7a1edc22fd2e8cf_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:80acc20087bec702fcb2624345f3dda071cd78092e5d3c972d75615b837549de_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/oc-mirror-plugin-rhel8@sha256:f7178adbebaff0ae4476c51d80015c678670c9d699f0ed74f42e9c73f62c3f42_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:2848be9c956f25a45c7205ed3f89889fed0e4e3b9e986b7ff6af59368a929da0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:63898c5855725e5dafc732da92f86b47f835e04b4cad0103c2e785a6aec3749e_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:7c5c23b3d2374c528d1fb1b46e3bbe260a9ca3ee3579b549784b6cebf5cce5db_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/openshift-route-controller-manager-rhel8@sha256:cc322f5b0e297a980160f1ad5e84b4e7cafb08e1db53ab9f490c05abd6b415da_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:0c691aa8d4779110598fd05b7fe2dcaf92782ebbe54678d3651357edd2de6b0c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e2c70fca183e380c6121a1c847806f11e839482123277235a8579db472b9ccf2 (For s390x architecture) The image digest is sha256:bfb67b8051cd35eac7d35bc7b190a5bedd33ab4ce90c9935b5d5ac59f85c03a2 (For ppc64le architecture) The image digest is sha256:b974830f0dc0fef0673a04c13bf24cbbeca2dfaf3c488de77f9dfa8169c74cdb (For aarch64 architecture) The image digest is sha256:19f4307a81793f66a4b810bb1e3a5037269b5b03397d0d5aa3206f883f991664 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (1325)