RHSA-2023:7469HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.4 security and extras update

Published
November 29, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp

🎯 Affected products179

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:36bce6157732ae60f58b3aaa260112661d800c23820100b4a364f538e36f5a23_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:a450e3bfadb63712df8aca1a79b8c3e391758cc85fc3d0dcbcbcf2d4be1870f1_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:ca4b82988d0d748a09f5187699a8e5e7032eba16501a6cdf10e793a9d9beb50f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:01a41fe47634cdeea9e2ecd1799d06c6f7505ec20f17975c38d30541fb0036e9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:1522417d56f77c4b80171d59bceb3a14eed2ee9861f6855a0410a64443aa33e9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:ae47cd02dc550d76fa28542333dcf527b9d299cf12da8184f0444163e2242a76_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:f1623964fae7fc41a9749b1206f7bbdd1770cdd90985a9e9cf7258bb27455bdb_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:05f238cf901e3caa0a790d8e6baddd1533a481c54d851276b86b443ea3aee718_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:0bd3c2f36d5018a1aa3c5409035370b8b8501ff4a8f60c08817a1642db748130_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:10ca25b69adeff0bea528133304fcb0c99f3b6599b72c4acb36a5d7502d62c56_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:b71c80ec493d59db401093ad6803d4c777dc7b00c1902ce68088c16c59c98f93_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:1004f851ffd434530d903a7cf22dcdbf5cd4f70464fe0fea673e2d024158953b_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:4d681d495a0746267c0d44b07e2b577065ce8d42fe0123a0bea9dde2d7da75c0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:6d0a65db44a056ce7be869e8fcfbe5308d5e0d3d73a00c0dde24c14584976590_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ingress-node-firewall-rhel9@sha256:dbebd62aa4c707631cf1fc4dbc6aa6b5699052f68e3a2459d9a477d0e7984738_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:15c7959a59e39e92557ba5c02b9f4d7870942ce53ec4f24632763aff524c1f51_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:33666ce9fcbd50945e9edfcce463e38af97b768db6833389b191f9d472bd85cd_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:be9e646a80ac0804e4a2895f56930aa8851b13ad6a344ab42d7d09fdccb13f9b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:dd08196cbbde1f8a8c597541764fcc4091468214bf020d1eee1e6fc0d4306cf4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:6c5fda2abf62ffbcd26f76cb0452bfc63802d3ea3bcfea31a5e95688e52b5948_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:789e69881070a24d9ce5aab9b3e2388bb6aa317aee7b8eef1ad81b6dd63fcaad_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:9842bf98a1fc232be7759dccfc580b4dde9bbb5c5c89ad2ec175d3726daff41e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:e0b86b33f2500a59ea207bb3e13e6e5f3124ff2cdf3dac04862dfac27bed202d_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9@sha256:3d819a084c870dafe60716f868bc646b99bbf612d9778eae322402f377609182_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9@sha256:69c10bcf74cc184fb52bf114b1f82501ad3a38ff3baf0d2efef60d9dfe65d53c_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9@sha256:81e531dc7d130c5f39fd53747b1fa9f7031ded0d9f3842866083fde72a4a3449_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9@sha256:9586e53a17b6bb1138ce8f0d1964cc5ac013190ac7a6b067e6a8bdaba0ee6b2d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/nmstate-console-plugin-rhel8@sha256:2fd412554f8c8d2cd997462ad6de5c0a31dc6aa0c55d22e4c1bb1b9016966940_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/nmstate-console-plugin-rhel8@sha256:4e39e04bb2e1cf76d818cec567a0c815f06816477d3dad5afd80c6446a5bbd39_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • +149 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.

🔗 References (5)