Red Hat Security Advisory: OpenShift Container Platform 4.15.0 security and extras update
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products157
- Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:1e270966ab31fb43205a02d6469bcc938f171c3e2a600aa65e47e2b463a0adf0_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:5bcdb5c8737114e6d918d67a66e74505b97fb5fd70ca083266b1aeaefd928e9e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:7dfd2c45e461e6507bc76a3072c4157fe10963a64e900ba30ea4961e3ee19639_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:98e1e06c16baca35f43ff4e45d618b18703e3a74b1ac8c389941f9bd77726742_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:96ab8b20da521081f035e2a8580e6183c587e65c5244687d69f070ab4ff16d9c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:a6c1dfb0fca561169a4a475ac78dfca985f714a9a6adeaf3b5b5cbb30639b65b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:ea1d3abcfdfc327ef4fdb5aea586c3437a50d3082a03984224059cb8ff6ad713_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:f6664ec43030bfd61f3739dc3ccdc3a0f867f985a139368491f3583622313a5a_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:2ab48778c51ca4c0024a33001f8e71db6ca96650cd938a991b72d41ce2f68031_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:58db0278f91930bca8190e3cfa46abce885538652b3f32038fc934e9d549dc61_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:bb6de37d9924be10b06e3f53a57fb880239d6a652ffc0c24adb5cdb7f6146762_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:ff9dc2a7897fc0cb8802ebb7f7ce8cecdc6f6f948b507cdb1f6fd9f91cba4976_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:10459e79cdf68fadcb056416fd6277789f3ec7cbac37ff87699d4963e49131a6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:31ce76b57cbc7339e754e34a085831cb16735d1b59cdb405f72cf642b35db71e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:52645af81aabadf6404c5974cf35e1ddc0946bdf890afb1fcdeb96edb6deace2_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:5ce0b39a256819f1459d61cf69f805bc10a029e02f27022911d65f6d1b2cfa80_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:1303e54eaaa3503bd4482c47f725ab43da0a5f3ea4fdcf485531a366f8624df6_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:313a54a383d831eb448ae91ffbe7b156d911eb28cd8d9f3517725c9f743e9d91_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:4fb5788e36695a9dfc8adcf414723926e433a94d62e1b315be9af340a1ff2a33_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:a1c5dac1bace559b082fd63fcb62c8b85bdd042a2b9c49cae79503470fbaa238_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:50f2a9a0d208ef429e25a8a7a209dd10156d3a0545c73fb4083a1f3ddc09941b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:6cbca9010e6f58c6d5eb140763a99f60a64a5c8b3eca85fb6d30c9ce428ee9d8_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:6e3ef6523c134878f76bab0abc48c72c97e9f7f91ec95b39f93c1bc139e8c9c7_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:a5ba4e051651cf91bdae8171f3c865b58d9936c685dc94b032093c669452678a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:05f8794838068454c35d6b21130ac451619fba186c0ded84c45d41752cd272bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:447c76d5bf5256bab456aadf3506ac4ec3e76ea35a256f089bf2c5117ba086a1_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:8cc50f1250439e18d03126b0719c93f562fc77e1300d67f56305402a14cac499_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:97cdfcb47579274394fc573575fba3c38e31a47412447a609cd0e24a19958468_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ansible-operator@sha256:4f1e93d4ca300acd13b545b3f591c7a5c83e7cc6f5d5747e212dfba8243c9352_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- +127 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (49)
- selfhttps://access.redhat.com/errata/RHSA-2023:7197
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-12887
- externalhttps://issues.redhat.com/browse/OCPBUGS-18177
- externalhttps://issues.redhat.com/browse/OCPBUGS-18923
- externalhttps://issues.redhat.com/browse/OCPBUGS-19104
- externalhttps://issues.redhat.com/browse/OCPBUGS-19105
- externalhttps://issues.redhat.com/browse/OCPBUGS-19141
- externalhttps://issues.redhat.com/browse/OCPBUGS-19153
- externalhttps://issues.redhat.com/browse/OCPBUGS-19194
- externalhttps://issues.redhat.com/browse/OCPBUGS-19245
- externalhttps://issues.redhat.com/browse/OCPBUGS-19404
- externalhttps://issues.redhat.com/browse/OCPBUGS-19536
- externalhttps://issues.redhat.com/browse/OCPBUGS-20211
- externalhttps://issues.redhat.com/browse/OCPBUGS-21604
- externalhttps://issues.redhat.com/browse/OCPBUGS-21875
- externalhttps://issues.redhat.com/browse/OCPBUGS-22250
- externalhttps://issues.redhat.com/browse/OCPBUGS-22387
- externalhttps://issues.redhat.com/browse/OCPBUGS-22704
- externalhttps://issues.redhat.com/browse/OCPBUGS-22728
- externalhttps://issues.redhat.com/browse/OCPBUGS-22903
- externalhttps://issues.redhat.com/browse/OCPBUGS-23247
- externalhttps://issues.redhat.com/browse/OCPBUGS-23950
- externalhttps://issues.redhat.com/browse/OCPBUGS-24088
- externalhttps://issues.redhat.com/browse/OCPBUGS-24119
- externalhttps://issues.redhat.com/browse/OCPBUGS-24130
- externalhttps://issues.redhat.com/browse/OCPBUGS-24300
- externalhttps://issues.redhat.com/browse/OCPBUGS-25407
- externalhttps://issues.redhat.com/browse/OCPBUGS-25411
- externalhttps://issues.redhat.com/browse/OCPBUGS-25691
- externalhttps://issues.redhat.com/browse/OCPBUGS-25924
- externalhttps://issues.redhat.com/browse/OCPBUGS-26496
- externalhttps://issues.redhat.com/browse/OCPBUGS-27073
- externalhttps://issues.redhat.com/browse/OCPBUGS-28390
- externalhttps://issues.redhat.com/browse/OCPBUGS-28716
- externalhttps://issues.redhat.com/browse/OCPBUGS-28752
- externalhttps://issues.redhat.com/browse/OCPBUGS-28914
- externalhttps://issues.redhat.com/browse/OCPBUGS-29101
- externalhttps://issues.redhat.com/browse/OCPBUGS-29172
- externalhttps://issues.redhat.com/browse/OCPBUGS-8266
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2023_7197.json