RHSA-2023:6779HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Pipelines Operator security update

Published
November 8, 2023
Last Modified
September 15, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products93

  • OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:5b6015d505075fff67033cce64ba85931f90bf9dd4b3a5b5f3f8cd618c60b13f_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:5f964a60593f4e8f96c01ae703bd6748fe0c0f788f75dda4e357ee32db8016df_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:5fda3388d67459119980528fe03d5895310e1153c8114a08a3b05bd9ecdda687_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:f58a1bd922aac35c35368ca4b3bd33908070c408aaf895c69dae6ca369e3733b_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:0303f01d8b2f3be3c09a6bbde001d40146ea459ca3401980af5ed0d0745528c1_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:5da30a15ec05c5651ccdc8256c5f0e2983197b1aacafc51a8d5fff5a59dc78fc_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:80cb3805280e496b99f459189cd28bd70303fa4f78c41e8efba18a15e5b383fd_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:ccc4687dd3054f00af5ee927ac9410d9445a8e1a54aeb58cc2e79246c8ea83ba_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:18f8d9707850a4624764e955c0f14f7299f3fc9b9ed8852036cc809b8233a400_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:909342dadd2be08b629e05ae79e20cc74705d51eb93330ae441ca160ab07bb81_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:d452c0a9759564024094bb1949d20c48c239158bb70d9875d9e66ae03e83ebe6_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:e7f92b0f53d1f04b153b42d34e156da11e0794fc076214394595c476fc85431b_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:0064ab030aa6f1839bbc3dfd157064adf75e470164f902c00075127ca50d856b_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:657d69d0bdd7006462a81cfb1b9cb16cc8eee1f2ee47203ca29fb54524dbc1cb_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:84609ad6fe8c76ea9f238e253ecbb9eb8d02da08a7826917ce6a55c681f8e1dd_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:a38c3344154fa7b2bfdf2f48e369aa26acdbc4b404be995aa35b685871c8e52e_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:a150b75b8e35cc3f4378122d2e1ad93dc4880488aeb03ca78be7a4f8ab3d439d_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:ab0c47cf9bbf4fa18dbf314959e37a37bc03b555ddbfeaf395b0cf1bbac1d38e_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:bec90770d8f779bcd8ad00eeac03eb30d3a37ba9d89b885dbf11aae1179faa90_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:c648fd4931eab69a12c96ebfbd1c603ebf5c38609d490c66495f3c39bdb1bb1d_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:0170d82ad87d1711060c8deecfe108e8191a2a2215f384698b7337768e062515_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:40e78ea2e906d9e2e1b74c4731b428c95a1a61bb764e6aeb20189abea166a8d9_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:631a5cc9a651a114e09c26e5c2780679afc1b5d64e93a091237ab05d9c8e33eb_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:a9c70d7dfa56252cba6789be6eab48f4c8ee9c1d7bf74f27328393bf0f0ab7d2_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-ui-rhel8@sha256:16a287c22d6590e2c3fc6c92702483f8475696be34e4210165beeb9ac69ad4fa_s390x as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-ui-rhel8@sha256:2dba2b7b58ce3a34a8fd244ade29d9d979d6d9d4373230827522c399cdd34a22_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-ui-rhel8@sha256:9e5123396252d9c8173b47d8b7043e19b09cc9b124c2ba2472d63b2f2996a24e_amd64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-hub-ui-rhel8@sha256:d62f295e4f46fa0660289f0fd65c18124cffcafe119d905f935bb15e4a7ce94d_ppc64le as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • openshift-pipelines/pipelines-nop-rhel8@sha256:146924f960674b80d7afe465ce84bea7fa5742992d33e19e94254e4a1f02039d_arm64 as a component of OpenShift Pipelines version 1.11 for RHEL 8
  • +63 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (8)