RHSA-2023:7198CriticalCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.15.0 bug fix and security update

Published
February 27, 2024
Last Modified
May 23, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-26159 — follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() CVE-2023-30551 — rekor: compressed archives can result in OOM conditions CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-40577 — prometheus-alertmanager: UI is vulnerable to stored XSS via the /api/v1/alerts endpoint CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45285 — golang: cmd/go: Protocol Fallback when fetching modules CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

🔗 References (1064)