Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.12.1
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products5
- Cert Manager support for Red Hat OpenShift release
- cert-manager/cert-manager-operator-bundle@sha256:140dafad28aa23ffccfcd87ff0674aa9fcbd904194728a9ee482bfa2d8d976aa_amd64 as a component of Cert Manager support for Red Hat OpenShift release
- cert-manager/cert-manager-operator-rhel9@sha256:7d3029dbcbcbec5f6b257afc8866c0b87bc2c694dc7f3fa7ad9e88e2b61cb3d0_amd64 as a component of Cert Manager support for Red Hat OpenShift release
- cert-manager/jetstack-cert-manager-acmesolver-rhel9@sha256:4db42d2b0403b2ae116c52cfa95bc54d621200072ad2c584a38a8e0e9b6e0a71_amd64 as a component of Cert Manager support for Red Hat OpenShift release
- cert-manager/jetstack-cert-manager-rhel9@sha256:1e3f9343999d6ed86d052688623de31fa74eee6f0b1a747dac32b661ec714b00_amd64 as a component of Cert Manager support for Red Hat OpenShift release
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to , then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to , then you must manually approve the upgrade to the Operator. See https://github.com/openshift/cert-manager-operator/blob/master/README.md for additional information. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2023:6269
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://issues.redhat.com/browse/CM-213
- externalhttps://issues.redhat.com/browse/CM-224
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6269.json