RHSA-2023:5809HighCVSS 7.5
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2.2 Product Security and Bug Fix Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products8
- Red Hat Ansible Automation Platform 2.2 for RHEL 8
- Red Hat Ansible Automation Platform 2.2 for RHEL 9
- receptor-0:1.4.2-1.el8ap.src as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 8
- receptor-0:1.4.2-1.el8ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 8
- receptor-0:1.4.2-1.el9ap.src as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 9
- receptor-0:1.4.2-1.el9ap.x86_64 as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 9
- receptorctl-0:1.4.2-1.el8ap.noarch as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 8
- receptorctl-0:1.4.2-1.el9ap.noarch as a component of Red Hat Ansible Automation Platform 2.2 for RHEL 9
✅ Remediation
Red Hat Ansible Automation Platform Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.