RHSA-2023:6243HighCVSS 7.5
Red Hat Security Advisory: openshift-gitops-kam security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)
🎯 Affected products7
- Red Hat OpenShift GitOps 1.10
- openshift-gitops-kam-0:1.10.1-22.el8.aarch64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-kam-0:1.10.1-22.el8.ppc64le as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-kam-0:1.10.1-22.el8.s390x as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-kam-0:1.10.1-22.el8.src as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-kam-0:1.10.1-22.el8.x86_64 as a component of Red Hat OpenShift GitOps 1.10
- openshift-gitops-kam-redistributable-0:1.10.1-22.el8.x86_64 as a component of Red Hat OpenShift GitOps 1.10
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.