RHSA-2023:7315HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.3 bug fix and security update

Published
November 21, 2023
Last Modified
August 24, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products125

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:3c774fa85ae1c6ef8926e9a1f1a1831ed0474511a6c1975fe24fcbd6cc118edc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:5d8f215f79ae57a23d2627062e6ee08c48bf77ae17e1ac969d5cc0b6ce5295a4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:c6896bab5071ff6839b2cfb66544c9a6617428069f3ad8b2d3710d66ad88676d_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/driver-toolkit-rhel9@sha256:fca57a24b162f5e51f6d5c77d0867618ef9c08d23c27fc25f5bf3fcda602b134_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:1edbd96f70f64135d6ea8bbbfa8afe73b8fdb10062c88167aef825d19caa881a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:d2b9f1ca058a89a649ddad44b251f35fda5b52b725c496d769a71e46dab73170_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:32889e3e6c7e74ff6a9a19a58b5a4d0f04b24081dcd7b69a3f9a4cbf9f0e88b1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:784175e0ab5456487635167044940297359fd6554fa1ffa38126926cd83fc483_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:7d2e13a2934ea3e20cfac8b58e51514d0411b1023e36d9a4c03d198bc34666e5_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-baremetal-installer-rhel8@sha256:cc4d3838ef3c4b9a5d5ffa05ae829c1de7022c8cc16f9d785a161b9c90b8dd49_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-etcd-rhel8-operator@sha256:58f2369af42352c8fa2b731fbf55343ed160c881673e2501fab2b1176a9b32ec_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-etcd-rhel8-operator@sha256:68cffb4387c4d114894666c98db66b8febd2b80812c1773c2ed3cad7f9bd1756_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-etcd-rhel8-operator@sha256:cc062bdd692eb4933b7496412d5122fa6d185295ad65cb18d9fb06a417ddf33a_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-etcd-rhel8-operator@sha256:ffd89303a3766bc4aeb2bc18b3d81249f59e5eec9cc7ee0bf1cff446d162515e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-monitoring-operator@sha256:12cbf97240f7d3903de177c03adf888604c7c8deace205493cc59043c9b65280_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-monitoring-operator@sha256:1556e2ac5158eaa5b31eca00997dcc0cb3ad01e69ab1dd96c7d3dc123dbeab13_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-monitoring-operator@sha256:3d096e082dc5241bddd6c495b2a634334831287b9b472a52389c9d287c682ff5_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-monitoring-operator@sha256:faa7ded3f5ad71545ab11707594dd1d171fbb1491886a9705d2702c8f00934d6_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-node-tuning-operator@sha256:3d183a462d7b0ef842018e9901e6bef07406dae30d37410a1bef2ac5cd37def8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-node-tuning-operator@sha256:d705034c2adca20d90af7452de521d75b954d09e09bcbed0720ff00c05bf329e_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-node-tuning-operator@sha256:d81633a941c074b3d036e7785e41abb46887012899dba9b89b531c283a0b9480_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-node-tuning-operator@sha256:de68d103ba913414c9000762bcecb64a3bdc7f15a0572d321f7485c3943b1fbb_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-console@sha256:0009c2c68fc28070147403fe282488b300fbdfa4589cab50822c20515951d117_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-console@sha256:079a8d5464451a6e6122b3c4804d561e8319cb755feebd32bfbe2525b0efaad6_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-console@sha256:5ab1254cac9d0cb03ba2ca2f6dcc9bd701ffac0ab2e00ddf515fd414203754d7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-console@sha256:c10561d95ba2e669c4e1b9519ab951f4dd079a4cf9681138ddaadd10f283ea5e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-container-networking-plugins-rhel8@sha256:0c751c2ad31d7927996ddd5eedb4e7dc5ea1dae8e0dea63d391cf62e26335263_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-container-networking-plugins-rhel8@sha256:6825e9af741f952625fdb29be751c0d68892b4a6322146179bab4a0b51c7dd20_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-container-networking-plugins-rhel8@sha256:b3654ab2f770cf120df8ba5d7c9692fe008c278be451243fc6ae9e7502a4011c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • +95 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e73ab4b33a9c3ff00c9f800a38d69853ca0c4dfa5a88e3df331f66df8f18ec55 (For s390x architecture) The image digest is sha256:300ab8d800e202b21096b5ecf742d39b433086b1de5b55b26b483eb09001c40e (For ppc64le architecture) The image digest is sha256:2331de76ca0948df812afa82f02d3a501c86b03d196410e21b5064fcf94cde35 (For aarch64 architecture) The image digest is sha256:8a1d195efbc3caf07a47b4d285166cd7c73337c90f191986bec8beb6ee27b4f4 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (30)