RHSA-2023:7663HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift distributed tracing 3.0.0 operator/operand containers

Published
December 6, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-46129 — nkeys: xkeys Seal encryption used fixed key for all encryption

🎯 Affected products73

  • Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-agent-rhel8@sha256:21d8fa0f0a030ce27c9587d647b7e3cbacd83b416ccbebaee10d1d2c9ab9f7d4_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-agent-rhel8@sha256:6051b1c3f9238bcfb496df7ff68638f8e14483ccac30d33fb0ca590b0f946473_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-agent-rhel8@sha256:e9ecc93a6226cb73a9bf7402906586e24a772269a9bff5365e5c67caa080658d_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-agent-rhel8@sha256:f416a0ae5e029eee58e4c02f102e95f80e45402bd86ecd8b0746a2c700f736cf_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-all-in-one-rhel8@sha256:0c763ffe9405b0928dd5916b71486f888ee6f37754e0d3f9feb74b25f617a2cb_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-all-in-one-rhel8@sha256:100cb4237de731039f1689a98eadce7a4ab32610585b88bd39421e5bcbc4ff0f_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-all-in-one-rhel8@sha256:469143ab1b29cc73db41e7c2234d4906ee5eb4e1179431a35cf5728361d3ede4_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-all-in-one-rhel8@sha256:ecbbab7413c79b4c17946a5cf5fb75be4a1ae8d3b8cb81f0e4512de14e071d8a_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-collector-rhel8@sha256:96235c48cc11499f15d22b4919823a648c73de381abb1506a5f1c40309d10b18_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-collector-rhel8@sha256:9d79b4fef8b2a58fe840a73a5b5d045373b2aa2ad4b5f986db0bff1e8ca8ac01_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-collector-rhel8@sha256:a081cf48c42de0dfcaf04d6a5f8eb24f9e638a10ee94e1146c83a95cf0aa78b4_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-collector-rhel8@sha256:f0cf2e3c77374cb318bf8b69fa6bd8c1478c967598fc2a59174e0955d220c36e_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:11a13b30564efabdb7dd6c55ed839c2bba54b220d8d5c39948df76a433fd50fb_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:bc4d0bc9f7d35c6f94df03f095c051994be2d690379e322eff7d9a570257bd5c_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:de28c8131fa2b6f7fba1b246557c13c4fc294975059c899972bb692c14d30012_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:ee207170af3cbedc86820c205a84ba07dd8b3a85a365f77642e6a3a8a8bffd01_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-rollover-rhel8@sha256:1cc081f4533b9e2364685bd69d75f531cf2e642a725ad4bdf2ba8391e0e25f3e_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-rollover-rhel8@sha256:1f32b8c6c75f703698d4e2651940eaf7aa229c98ed8acb0efb9eb268b83f1715_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-rollover-rhel8@sha256:6a9f07800179639aaf394b1e2b00ec6ea2d9c698329c40c9e9e7fc805c9250d3_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-es-rollover-rhel8@sha256:c17d71124489396b026e507f126fd0e701fbeffe5fcdd3a2cdec8c391d0514ab_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-ingester-rhel8@sha256:4975a52d66395af440ff4148bd93d787ab3b16787025e7e2336074aa27761120_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-ingester-rhel8@sha256:977fca15a589e7d6c0575abf6224387da5edb1ff3e09c2f90e6c4f2fa20227d7_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-ingester-rhel8@sha256:bb9d9b51e657ccf37705a393cd8efd0d6880fbfc2bb484914652a43c39695f9b_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-ingester-rhel8@sha256:f42aba536e71a6168bdfecca1cc5bdf4f41b02eb172a6efbbd63d6cf1053e033_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-operator-bundle@sha256:110ce786fa2f997331c889d314fd136b68683a00032667bef797cab27d20e32d_ppc64le as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-operator-bundle@sha256:925087209f7c167f02573a1941a2abd401a99061282be964e59d24271d5ed998_arm64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-operator-bundle@sha256:af0f7adabe6617aa366e69a53756d0855c9f00bd973b0c1d8627845820595d30_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-operator-bundle@sha256:cea64466e14175545417779cfc72e2a7394f911d26b3abc223d8930cb37c8642_amd64 as a component of Red Hat OpenShift distributed tracing 3.0
  • rhosdt/jaeger-query-rhel8@sha256:49b45c0ffbd25fa21989966120c9ea162a90f181e01c2138cdc4fb294d180bd8_s390x as a component of Red Hat OpenShift distributed tracing 3.0
  • +43 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.

🔗 References (12)