RHSA-2023:7555HighCVSS 7.5

Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.3.0 security update

Published
November 28, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp

🎯 Affected products45

  • 9Base-OADP-1.3
  • oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:0d0b1ab0e8c287286f19ce71d9aacba69510826347f4dda5e0ff7a2be0ef6c88_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:3970a66b4525a97ef6ee39fea1570f7b81b0529b281d05d5bad82e2c2261b00d_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:5b149e2f215085f5b969bde093fcac250682d48ccd2d1e671d55e945e02c5c24_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:f68841818eebf6fd794a4766fcaddacc7476b02e5248a25db45ee325b9dbd682_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-mustgather-rhel9@sha256:1979b2e3a393a936063792a4dbdc52a429b3015a5c661dea9041954aba46c567_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-mustgather-rhel9@sha256:474ed76e1544436e6708c029329f4cebc72efdcfb2e2df751c3cd917224a8e4a_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-mustgather-rhel9@sha256:71ae5ff534f4f67cf99dedc3c21b247a3e88749fad856249e7ad746518671667_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-mustgather-rhel9@sha256:8fb3cce0033e3de7fc67e764de96773eec18f4184cd5f9ddf4b0cd2b2d953220_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-operator-bundle@sha256:27778b1cea8867d0e5a1dd400fa4e605161fbaf7fa1e9eeacd63522bfd1cf5d6_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-operator-bundle@sha256:3059a1db6a7041bad8c656287d8fcafc478ac15656fe95d030e9bafa967e8d9a_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-operator-bundle@sha256:4cde7e9b893b3a9b5c6eccb5496701d1601046cc1487f94d28bed3b0538e9957_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-operator-bundle@sha256:50e6ff903856253916602dbb2e2fc5d0a2cf013fb710af1fb618c09aed30d09d_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-rhel9-operator@sha256:063111faad5ce211e11c5eb2d61559d0b9a89178cdf86377e38599e7232d55d2_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-rhel9-operator@sha256:a4995bf30e14bcc454a978199f4b6b9fbdcb5668dd80ebaa05cd8b4d64486856_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-rhel9-operator@sha256:d6361b290e08f9bfc22d902587206ef81ebdf9e8234475e7b846bb165c6029ba_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-rhel9-operator@sha256:e1cb117c57176aaa30641b849a95a23e737215e15f1be784f73870c1f2be02fd_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-aws-rhel9@sha256:24a009a20c555e5da425a4127ac944907db6a70e733bfd7d4009406430d2e615_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-aws-rhel9@sha256:486c3b2f1e8a16986309966473aab35a7aaaf490a25c151ab534a7c029ebd3f1_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-aws-rhel9@sha256:a355c4029f781a38c9d0878fcfae79191751aafe63a88d0f7b00df66520fac6c_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-aws-rhel9@sha256:be8c3101ff144d717007d7871457df69e1158c993c8b4fe5deac7294b939e3ee_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-csi-rhel9@sha256:0e82ac7f8380539bbc82507e7ef55d9a97d79eaeb8c3c0ada81e6dddd29b19eb_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-csi-rhel9@sha256:2a9f38ceaf22ef7d06a072b6a590a63ad7169f9e5936ca81236723cae5f679e5_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-csi-rhel9@sha256:6b59f2d1dea625fc1e14275083542986e3d53fdb1dc1d934e3f1f2fa2c90fd5a_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-csi-rhel9@sha256:857e46130a3b0be6d76d45531518e44e59d3a10cfe635fd602b1e28c1d9f5ee8_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:5d7cb76f4424c2208d9aee8368b960137d69d173caf88c1c5c63b1880374550b_s390x as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:702008d74a7ed324d1da2ac20e2358504bb04d6708d2703a7ea65414450f201d_amd64 as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:d8772fc1fb3f4597dc0e0c0de6986cd0954a61ae67830d01a1e3e7ecfef0fb22_ppc64le as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:f950bddfb84693a35c98df847c1ccf486a4c480207f50b6836b0d0da1cce9e05_arm64 as a component of 9Base-OADP-1.3
  • oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:1016fe7844ac9bf28c07b8c0d74acdf62854d2bed8319047e557973569d44bbc_ppc64le as a component of 9Base-OADP-1.3
  • +15 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.

🔗 References (36)