RHSA-2023:6118HighCVSS 7.5

Red Hat Security Advisory: OpenShift API for Data Protection security update

Published
October 25, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products53

  • 8Base-OADP-1.2
  • oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:1eba8b3a26d43f2946391817f37cdd8c64415f65108acdfeba66ef9cfebcf0e0_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d79146d04177eda5ccc777815932fda586542cf53e88d2069b980d14a3bccfa8_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:d98265aa2ddfe8a051e6e332f450ae4007e5f719eb456b2db582fe095f7cb88a_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:e2cecef9337f9aba8285a8d917e5cf75e24d93d44197578f93a497eed309d94a_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-mustgather-rhel8@sha256:4410001b038f57f2b53a0aa8a7187db960410a3e6091b4923c0b1924d3ce2592_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-mustgather-rhel8@sha256:5220e6df18cb18dc2d566bae6b49ced636d9627a111f7bb042ebab3eb0372754_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-mustgather-rhel8@sha256:7d66d863ae6c46e1701ed0c55a7ebd5eaba3d0a330fed5dcbdde5d5f0c5c889d_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-mustgather-rhel8@sha256:e712baa2a2a94afc004397d10fc6f65334dc3a4c547a97ecea5dc96247d28d4f_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-operator-bundle@sha256:22d1ac29ae9c3b35e4f850cf26cdcbdf61d5630a1a9aeed079c2dc8f46bb7434_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-operator-bundle@sha256:42d3bb0d645e427380af3f100307fb1aace330ed107a35961d30e2f3a1ded213_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-operator-bundle@sha256:912b4769343594442f2eee159d52a61ff72a559628b57002cc9fedf7fab7d992_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-operator-bundle@sha256:dea1e97ee88949b9692f2077f4769b214031366f72f392cd89f85c0c7dcfffd2_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-rhel8-operator@sha256:4628ec389b445fae40227657c9b1b6330fae7a9a76cf80798c4c7f74181050f9_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-rhel8-operator@sha256:7572bcc6b877c605805601dca3a6daf8c74b4c82defff9d53dd4173abad84e85_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-rhel8-operator@sha256:d610d59b4d11ca019611a80ff929cea304a333c78ae8339a8c24628daa97ccdb_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-rhel8-operator@sha256:f1ca2345c320ccef8c1336e2b4caba0c97e6d455e9f1c70cfb921b07d26e9024_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-aws-rhel8@sha256:64777c17edf16c46a0519a6a3a479e2004da580f5f1b9987d3464894cdc3d621_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-aws-rhel8@sha256:6876a1fbf67f9b91ef0cd8442ed56a2b3be79daca4f30ab583c4e95b6179b935_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-aws-rhel8@sha256:81072079708e5808b6a73d8ad9fa6838680a90565a64eed263dfac62eb074f32_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-aws-rhel8@sha256:a2118e62fcd7dfe8e65b0b1e9df909da3a6317137d2097f4c4ac335c80aefdfc_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-csi-rhel8@sha256:166cc137856090465797a03844a1ce0c7c5b315917264d1a3c570ff8630c097f_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-csi-rhel8@sha256:8ad05b4f05a94234566276f923ac3ef40ecc17d9e4d05821851b20e381d57bae_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-csi-rhel8@sha256:d5e564b3d10e44ae21a66f1cbe877b23f55ab397328f4bd168fb4340bbb1569d_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-csi-rhel8@sha256:fbc5a4985c0cdf01f6b4aa0d2c9e516f7da8f6a5a6e5e795076e3f710333bb67_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:09426f08a141993d299b940acf33c1065deba4f6bdf9d93db2496cdb043d2f8d_arm64 as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:31e7cdd4e0965814bfa1a5e07047e3b7ed4953c11bdd0b5adadf493d9b54b534_amd64 as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:3613dc6e2c0b94095d30deae7009f05245f55b01b8caea791d99f8492d751b96_s390x as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:da7601aa767656db6edea1eac57f8a891eebbf74155c395b569e2d4ff5d81269_ppc64le as a component of 8Base-OADP-1.2
  • oadp/oadp-velero-plugin-for-microsoft-azure-rhel8@sha256:44861c3facde9c65e656ae68a8ec6c8871252d6d7e585c37743f0625e4ca7d45_s390x as a component of 8Base-OADP-1.2
  • +23 more not shown

✅ Remediation

For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (6)