Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.0 security, enhancement & bug fix update
🔗 CVE IDs covered (12)
📋 Description
CVE-2021-4048 — lapack: Out-of-bounds read in *larrv CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-2121 — hashicorp: html injection into web ui CVE-2023-3462 — Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-5077 — hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products90
- RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:19066af2eb30877d010ef66b5d538749da1f0521b4a762871a53c57ead216e9a_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:35a02234cca01c1f4acc66744fe5238c1810ba098b63f95c5c09f183647032f9_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/cephcsi-rhel9@sha256:d256c07680a4463f09d4a06a000fe001806cde5ccaa958005a1a3e66a127b5b1_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:21d8549a1b42e78f04f555d4bf662da649e7411b54491055779859fa4bce2a37_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:52cadb4a29242624ef35270f56317e019ae04dda9c6710d9d944a8628ca00818_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:c354acbac03e2af6fcb7b5b1dbe16ab0a382004ef7a335f9327893138ce2e922_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-cli-rhel9@sha256:ee129f877f166acabe289aba862cd1d0154f29987dfd9df4800b18c005725256_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:0a9ccf86889c47b950246e2f6829b568b2f3cb0f37b2ad18282ff2a40f0448d6_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:4db0118093d6186245a1bad6e33a7c324adf4385ffe632e72ef8eb6fa4bc7cc4_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:61db6bf89d17320cb1de31b07905a67db6418b8bd5da3b28c105c30c673a69ed_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-core-rhel9@sha256:a3c88a63ab8c071cfd28aa97a12d2cf44f8d6f3779875b8bac79b76334995575_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:217ee67bfcec7b49193c035292a10577603397acae7b3d36ef2a8809a47c4b01_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:b2586abf037cc9a313b5b07a36806d27f8a5fdee8daf99a00ee491243085a7d4_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-operator-bundle@sha256:db479b0a4c27104c57911bead5d15b99617a2ae355586e765b04ea02f72662cf_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:45e081dc18d87532beb038ee07e9e99f3ab686ad5a4fe65664f82e490d295d14_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:5149a129f3caf1f0e93ce490df3e4bbab4d842cabd85556970349c81d1de6970_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:cf3caa9b68d92d8b99237dedd6631fbe96a30ce1ee44f4cc3eb4c9a45b5f906d_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/mcg-rhel9-operator@sha256:fcb6309f9244be94c6154d45f0a5c415783407064fee1ee48a4c05970054da1c_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:092b03642b8adae73f45ff264d38a796fb8a7fd89b87e712db0473f9ccda3862_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:0dbc5b109af0e72148bc5c70089e2db9f3a6a30946484ea2b75a05ed96b74049_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-console-rhel9@sha256:1a8a1d7bfa55de51ec2a777f2ad0d21d61c0e4a8be2802cbf4d76dc4a5d578d6_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:4c73760f7c2e5283d5fa197a95191d8e0568dbebfabffe476933a2545bea2b3b_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:4ff423ec1d18619590b5e3ce4b10352dbc50894ec92ec5d0164c8488e6f45a9e_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-operator-bundle@sha256:cab28a3e2b44dc6f2efebbd5a52dee943ac9a8ae1f52cd4455418a6b689d54b3_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:6b8fb443051345da399d48c5cff2dce22b4b8b2a9ab224e76d423d820151a8fe_s390x as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:7f0e8e93d13f4fd74c0e801b94c0fa79369f319e371832c59c990f80a02a29fb_ppc64le as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:923bc2abdbf6ad3594e3db6acf6a0054ee13deea7127480e4d200758cc2789d0_amd64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-client-rhel9-operator@sha256:bed6367b1913369a99f1fc690df25a592b86d1fce68e2b86ae71ecbea7098952_arm64 as a component of RHODF 4.14 for RHEL 9
- odf4/ocs-metrics-exporter-rhel9@sha256:309b5a86d0f438d93ca64d7eea18c0b69a33a345e913977e2cd6507ce54e4fc9_s390x as a component of RHODF 4.14 for RHEL 9
- +60 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (180)
- selfhttps://access.redhat.com/errata/RHSA-2023:6832
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1970939
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1982721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2023189
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067095
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2079232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2104207
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2104254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2121514
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2122521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134040
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134115
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2138855
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150752
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150996
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2158773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2160034
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165941
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2166354
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2172624
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179348
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180329
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183092
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185042
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189866
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2190382
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2193109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2207918
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208563
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209251
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209258
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209288
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2210047
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2210289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211362
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211491
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211807
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211866
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212931
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213118
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213183
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213550
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213552
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214023
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214288
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2214838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215239
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215917
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2217887
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2217904
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218190
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218309
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218492
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218593
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219355
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219436
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2219843
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221995
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222022
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222887
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223553
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223575
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223690
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223692
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223705
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224245
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224325
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225223
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2225685
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2226647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2227017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2227607
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2227835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228375
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228805
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228816
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230050
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230334
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2230447
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231074
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231124
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231709
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231838
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232464
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232502
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232552
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2232608
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233036
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233410
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233445
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233731
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234357
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234735
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235245
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2235708
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236436
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236445
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237213
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237226
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238895
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239093
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239096
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239140
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239580
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239622
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239776
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239802
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2240778
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241980
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245978
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246185
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_6832.json