RHSA-2023:6220HighCVSS 7.5
Red Hat Security Advisory: Errata Advisory for Red Hat OpenShift GitOps v1.10.1 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products34
- Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:16c949645ea3394fe5949b65ecb9ab8fad19b4e9394efde09e2e23daec86f6c0_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:27538a9192e7191ebc9ba66305d6fe6e424e86b47058664f03332b912f8f9ddd_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:a0fbcaa5d1f06b041ad2349c9823d15dc9c280303fb8cdee6430ac958872f2e1_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argo-rollouts-rhel8@sha256:d72a2073d528a99b5addb36e05d791230454b53e30161c0c6bb0f0a41ba44622_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:335cf1805d6c33e7a990c4a795d9ca254e82021d072664ce711ccb7bc9fa13d6_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:76f93939fa372439f0a0931bc77bbd5d74864fec41155c03cb0b31f8c902df5a_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:a32794dad3fa8963e86e87744ca2595cb40d958e42e5ed8149a18c44bcc1ee15_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/argocd-rhel8@sha256:ead93a1bcc5a8c497ad4042c9e539450b20cbfca49bdc3677e51ca1ba881c321_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:3d6e3cbad1ffca6f662e6130024a61982e6c6884199b04b8a469734cc0f578bf_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:671a50eb7cb6ec8750e72c30e0bd2f3b4a2252bcf8993bafed8e35ccd236f6dd_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:ca4b850c436cb203933d6e0fae2bd6aa13f86e084e34d187d532e706a5f87789_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/console-plugin-rhel8@sha256:f74a99192da67363a283815a3d1e941d643424bc906b06057a04c5345f8bc920_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:601d38d66c07145a5f4c8869c9edbe0a2934974f3a41e31e067a0db0da5dfd72_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:761684931f8b8cb178b7093fd0ef4c87d048cc1eccc47fb89b14d0464024a9c7_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:8f3d247e46e9d07759d29c7212e5900babe330d96d96b850fda19222e2202966_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/dex-rhel8@sha256:926121cfb5001b91cca137a5085553ad790e185090c104d64f78cdc8c2221c43_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-operator-bundle@sha256:954733d0c9c77cd42e65fcaa6b4b6f9295b5d43d2d81cecd82758f88ef2eb07c_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:5141a6d11f19dd426390c5041080da7f7a09eab6b9d87f7ffcb8e59483865088_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:88ed7760fcec1e50cab43be21ce8794cb64962a6dd1895be23c5fd53d7398950_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:a1072a2be6cdb5ca8d32761c9973dfa42c5037a45caea8f8214a78e438448692_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8-operator@sha256:e2610683d9e2610d4cd58a0d082cf2508bd8731136f17774cb6118568a5da101_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:139d076eca407abfa5d61a669ad60b0d57323eca0881dffc51b5b0fee2324a45_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:794cb8cb74169086528523427daec2fec26d9b2fff999d5dc1c453e36461a75c_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:d0dc555f70ce43308119c14b8dc9b6ca72e2ae6c91b151f144a015e624cb9e07_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/gitops-rhel8@sha256:f1ea4aba3566b827e4442c228fd8840e50443354bc676615dd33dd940cda3d82_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:883698f945e44879ac8d84639addcf213bbe1af61bca67020006517b11e22f40_amd64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:929b479de633cce8f697a2659c59bbb17827674e2c08a35ed16db44d3ec73632_s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:a2f41d3ee8c461b471dd2714add10c8f3bc6be59f3b411d5e825061c36df3e4b_arm64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-1/kam-delivery-rhel8@sha256:e4d52f274a14ad1c37b8b22a7c2ef649e55b2b03663ce83cb3ac7e386cf4472c_ppc64le as a component of Red Hat OpenShift GitOps 1.10
- +4 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2023:6220
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/gitops/latest/understanding_openshift_gitops/about-redhat-openshift-gitops.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6220.json