Red Hat Security Advisory: Red Hat OpenShift GitOps v1.9.3 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
🎯 Affected products34
- Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:08c50b13b7fd04f3756250ce727f75f9d8da1bf0dbb27fd2f1206850d9e7d0fc_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:5dda4516e7dd63cc711cd18e0569cdac873c2a3ae3bf41fd7645384e1aea0952_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:9afedd1e7109a88fbe381846a6a0a206b24ba3e62dd699aa750d4b7f28505080_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argo-rollouts-rhel8@sha256:b830502f20de70c8fc7f77a6c58409c00f6db79224f306f5f667fadfca59bd84_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:bd8aa96326b5c5e649634489941e19bc17cbe04bfeb00d1b362d7afe98277594_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:dd7e218067771217c00df8b4ed7b94faaa70f31596d8a8da796a1115f694fbfc_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:e432172e252f278ffe9d1e8bcf6c89c81cbef76e3755eb7b9f3d5ec4622a63e0_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/argocd-rhel8@sha256:fbd5576fa614602b26677e91136d0c9c4722e0eb09672e3784ebdfe71737d3bd_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:21bff8ab1b76db1507a96432d49df4e537ed66d1fed1c96434bde10bfdd62059_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:7c05fd1be9aa7427e565544975f7f85d4600c7eabfd22ff4f07e057e566496eb_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:84dee8a0455dca910bab7407bb8bc3151f788ae991aa9c7d9380e8c7c1a4014c_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/console-plugin-rhel8@sha256:eb9abd40236e7752cd8b5d215ff8619d73e1fd5ff6abd0884409dcd442fb4eaf_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:14b1e455f6ba59777aec0298b64a21cf40d89429dcbc3dd59ad2f30c649d6f5f_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:2c5390ab43937ee0f089f56bd64752aa7d477d713d2eabf17fa7a48b3244e573_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:ae805dd6858d45e042b335240e450c5f5635546381f2cf755b4d0049f80e4bbd_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/dex-rhel8@sha256:f58dc92bdffd95385a51ecdff7677b49cc85b0a7718ca5f69301e6711a9bf04c_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-operator-bundle@sha256:d8725149c57d5de6c5c10d472cfd54721e8f8bf12e66e34c0311103a835a3081_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:02bc04eaa379108c8cf99da5d89a4e8305ccb3c3921037c9b160d639c5c4de03_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:32da9518faee368da0902ba87c1ed95a03e75ea344a31c9af19a96a436a6ddf3_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:79f9227088dee48a79afd14732087c23ea0c6869c0dd167dac94365b225592ec_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8-operator@sha256:d491c7c8525393b4dc8277fae5639ee41ae4d6bbada83a212742e9683877f0b0_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:1e4441c4b21af05b97b4f4d5fdae767721ecc645a43f63611d18d3de87498805_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:21f03d5337d4177a908f63ce3558bc130a045fc45c6f6a4d2783de4e4b555e21_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:585361fa372d675855cb517e0305339f9856fecc7b1f89b31ad33bca3f9836b8_s390x as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/gitops-rhel8@sha256:97acdfe9b2fba3a37f01e91efb4074eadcec204414ae7f2c0a426b71af60288c_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:1c546c5cdafd6ca78c3f5cb51d76bdc1c139fdbeee3eae0799a2550920cd31a1_amd64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:6bdef15c447107069382c76cbf89faccbc116ec62c9be9231b0a8edc0e63c0a5_ppc64le as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:9903bb78e5d0cc39d314e9bdaecf902ac4d24bee3f11b7658caaa381253c81c1_arm64 as a component of Red Hat OpenShift GitOps 1.9
- openshift-gitops-1/kam-delivery-rhel8@sha256:b6864990dd11208362570ff7642baf33d96690a9547ddb71403f5deb5578a761_s390x as a component of Red Hat OpenShift GitOps 1.9
- +4 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:7345
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-003
- externalhttps://docs.openshift.com/gitops/1.9/understanding_openshift_gitops/about-redhat-openshift-gitops.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242803
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243296
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7345.json