RHSA-2023:5542HighCVSS 7.5

Red Hat Security Advisory: Logging Subsystem 5.5.17 - Red Hat OpenShift security update

Published
October 24, 2023
Last Modified
August 24, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-26136 — tough-cookie: prototype pollution in cookie memstore CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products64

  • RHOL 5.5 for RHEL 8
  • openshift-logging/cluster-logging-operator-bundle@sha256:b12bd9714a693251409de3f79cc59c3ea2b744eca288479942541bc091f98522_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/cluster-logging-rhel8-operator@sha256:09686a47d73e381c80003714147137a3d3b1d9672d507d26c35a486e17f95938_ppc64le as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/cluster-logging-rhel8-operator@sha256:51601c319a847410dd67dded9bfc3e177d607f9bbd955e40da14c0a6e18775d9_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/cluster-logging-rhel8-operator@sha256:54b85cd3a230c34372cc913711bf94b4a60fdbb754006310c5ded66e19bb546c_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/cluster-logging-rhel8-operator@sha256:ed66413a6035be14731ce10bde6f91023bde67e0861edf8f536c13e2101bf50a_arm64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-operator-bundle@sha256:2a3bae732280547fc5434a6d9910fe8f4f3e9060d6454f61726bbe2efe6facaf_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-proxy-rhel8@sha256:0c24a8b9b1d6fd2c0f831fdefbbee14d9991f561ea8196e8435d4c2b1b98c9b5_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-proxy-rhel8@sha256:122662e15f63bb7da2392343adcdac3834c9b47f510ada210ecaefd5336673b4_ppc64le as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-proxy-rhel8@sha256:61ad583d20b53b400460bd45368a2b91cccb3213a415d79a9ee879ac4447f594_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-proxy-rhel8@sha256:97af66b3e1fb61379c42d1e9f456f1e831595dd22f62dc70be2da10c8ea9d780_arm64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-rhel8-operator@sha256:07f46c6182126014df275c8cf64a2864ae1d887e58228c2c48da5809315e15fc_ppc64le as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-rhel8-operator@sha256:230a6d4dd1e8c7a0fcd485d450ec7ec7d1a29f3ad963f3e4d11cd92b9e1958a2_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-rhel8-operator@sha256:5ebb73023691a43b9bfc53543d87fc143ec11bbb25d5035bd5cb29e9526203b1_arm64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch-rhel8-operator@sha256:ceb0851250bd48ca908f038ae6a9df08530cc876054f3e8447c3b988b18da2a2_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch6-rhel8@sha256:1a6f54ae9b91e47bfcea27190ef7298f34c9d790964e0ee5e02d9807ce990a93_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch6-rhel8@sha256:459cf54a779336cfe71b1b4a790215ff8764b18a77b7d7cc3a89defb20748bf5_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch6-rhel8@sha256:8d0f3aa1db3f32885b1fa19a098b8aa225068df07e02a284639b732959febd84_arm64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/elasticsearch6-rhel8@sha256:e945d7c6263362ab92f60e0a328ef7e59bf89e996d3b4fdf7fb394c388c0d762_ppc64le as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/eventrouter-rhel8@sha256:1820ac83c516361553a0c9f9c0dc93ea2ebc1cdbb89fb980ca0d356892e8d034_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/eventrouter-rhel8@sha256:3b0cc80d9dcc51d33cbf40edf9ee590495621957472a8b5811a0106896ca088b_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/eventrouter-rhel8@sha256:7f785fc49c70917f744c2b36ba80d4cf8171823c5da9071da081955cae410859_arm64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/eventrouter-rhel8@sha256:d79bfb1655216dda89266b4f818941cebb0bba6d59edc299e43be0644aacd838_ppc64le as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/fluentd-rhel8@sha256:330405c116c6cc49d9e14ed373bc73f9759017ccc9d5cc984ad9241023778e2f_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/fluentd-rhel8@sha256:603effd18fc472200c23e6e8f49c2f9bc3e33a0ac9d951f28f52f5667a18850d_ppc64le as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/fluentd-rhel8@sha256:bb9d2ce71e2a9cdc09f7eacd5010d23412b68acedb5b828bd9b2a7e07c836137_arm64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/fluentd-rhel8@sha256:c0c053caabd85aea33f8b69bda2739a9288ed8b48554932c431bd6f5615a510b_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:042d7881b2e5d5544a97ac95f39adfefbca08dab6621f7439b59d640ff1d4b13_s390x as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:7f3a73273dd82f675f1abf2e1a767f7f59392571ad82ff84e6740397800b0feb_amd64 as a component of RHOL 5.5 for RHEL 8
  • openshift-logging/kibana6-rhel8@sha256:87a32dd0769e887e2c11766e7564d4d161f180019d28dd78d99fe48e18c53ac5_ppc64le as a component of RHOL 5.5 for RHEL 8
  • +34 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (8)