RHSA-2023:6143HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.0 CNF vRAN extras security update

Published
October 26, 2023
Last Modified
August 22, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-30841 — baremetal-operator: plain-text username and hashed password readable by anyone having a cluster-wide read-access CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

🎯 Affected products9

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/bare-metal-event-relay-operator-bundle@sha256:0b35b3886f9a25e5058d86a70b63f9b0d38058abb71aeda71132cf4be5094cd7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/bare-metal-event-relay-rhel8-operator@sha256:8ffd30964ccff8ffb5cde75379d08dbf1b79f4e15f7096d0cb92f40c0e6d4ba4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/baremetal-hardware-event-proxy-rhel8@sha256:538b97a6eff8d234c1890864b6e24cfa55a756282346f973e9c665ed26bfbd03_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:7bda597b994f59b42b2cde81f7db508ea9455339a8b67c57faa99fdf7d821b0a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:59e1c911cdba45b5a672d9238df1714c9a248f9fc8807da14ebbfe983baffdd3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:edf4675a849438bef46f73d06e284739686ac6fc99a8dab6884a8a2ff2956931_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:1fde5d41157d8ed18330792e8681f10820437dab16c6cf1585a8f5784c569803_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ztp-site-generate-rhel8@sha256:88ff959ff3579be2f80bb7722aa542674f91f57829f3374f770ed124385bde3d_amd64 as a component of Red Hat OpenShift Container Platform 4.14

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (56)