Red Hat Security Advisory: OpenShift Container Platform 4.14.0 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift-tech-preview/metallb-rhel8@sha256:102c4df27e85c41907b18710d919ef1463781ede4a10af3c10e7372ebca168ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift-tech-preview/metallb-rhel8@sha256:3d0673d6025b4dda0d639fb6510f437b244353ce9d232207d49456f5914bf5a8_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift-tech-preview/metallb-rhel8@sha256:7a5be510bb1d1d85029386241327c4a86521954a35009883c9da0ac38d271cc1_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift-tech-preview/metallb-rhel8@sha256:c8a4974d05c56832c3f06819ad40f54c23eea38b30c05e690d5f141c3a1753e3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:0bc06a8cd697f1c30be0e00856da2dba6248761da3320d44ce39d2b6112171d9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:6f3bce3913484baec69d840084264f523b4ec2d895f18adb59f44c4fb2cddb97_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:86176fd3ebab856853b3328d6de5c8231912a5649ed1445770aa102d6bbf16bd_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:24360d7c0c62a2868a0fcb8bb436fcb87f2e201b550c8caf832da1810daa9e2e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:349fba021e277d33e73e70c92a60a15c5179fb921ef780fad917fd83853f95cc_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:766b5f81a0fde804a38083f13048b0a3055baf0629c4fe496a946e618d46d452_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:cf10aa663bf8f59ddbbe2455e7617d21ce86fa05aaf9dd8c9cd745975895873c_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-operator-bundle@sha256:ba59d496060ca545580bac6c4526e9ffddbf279cb21156ca1215488b71c20927_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:0236373775ce3cbbacceac26d902e3e60675a67ca9f615393a96c527a41d31ad_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:a567a05b8a544bc02d01becc367e1b66f92550c580b881f660c618343f9b8bb8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:bd5ce80ab3911eaf2b7e4480b46718e0c5137671a930a221553d8f26442d1bcb_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:fba7de9080dfd6d8495d0286f4cf83c0dc3b53f5ed18dddbbd64c7881be6a11e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:3f332609d9d54a50fd836622aadb1fcc39a8c1179b752a01691a512c8989f8bb_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:a141a26ccd645d28719548bc91707f893b7fcbb8c17f1fafe6b246ce18023b7d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:d19f93778cddf8766e08d70f65f85e21a84994d263eb81fe62c53dcd7de7ccb9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:f1a5a54554e59e268b02494122edcb5e46fc0f59496949796fd236abda0a3115_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-operator-bundle@sha256:ca9540f74597f78216380c16c0477561806f7658649073801554b77b4b44ec28_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:47114667ce787bdd787ff302447c6fb89e765287dd7f3d60592f5bea90c9acee_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:477a4ac5a6229f64c418d73a3c7a2a6f61ad37a0d1b5ab37e4523522ccb1eadc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:ae93a559291c4d4db53cb673135a5c7b391895b1bab63e292a7cfed09775ae6e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:b5ce8728e1e8c31394d532560439b1fd90c1aa12d28e23cf90c5965d32ae2ee3_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel8-operator@sha256:19cf9af85f4aeac0c0a54fabffee07447605d1ef565359338da4c5e0c3d46664_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel8-operator@sha256:757f1f7707f896fb6f8e649fd53e749efe76b1307825c17e01f29875eb0ca182_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel8-operator@sha256:bfa8a413cc97302b4e94fd206f5571b78e372011a286ac1065db2075aec75575_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel8-operator@sha256:f11c84a801fe2f7f62ed5debfa7341be173b6a9df1b7cc84a558772371ae987a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Details on how to access this content are available at: https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:5007
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224245
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5007.json