RHSA-2023:7681HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.6 security and extras update

Published
December 12, 2023
Last Modified
August 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-26115 — word-wrap: ReDoS CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics

🎯 Affected products49

  • Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:5adefe64dd438bbef12cfec97582c762ab6d70063cea328349a19b91eee94a6c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:6c99194985bbea419b05ac7d849489bb43ce9c05007c529b0847812c90251982_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/cloud-event-proxy-rhel8@sha256:c50f0d3fdff38b8ce78967b276689cc32e4efe749ca19af9f17eb0dde672affc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:0c554f40009dfcf82ca7a76e02b3d31734bfe80a58969e399e245f51766e0682_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:653dca964b5bcf44a7a7fc2c585040e7de58e8f3bbbd6060524996571e299607_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:a4439d9d24b28bbcb842bd676838ae1369a139c2c3d38d39abd954b5acd4a399_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/frr-rhel9@sha256:b95920113883696201acba9754a932180c3194a7f36c36e04d813f0e16ea5cd9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:6a031d824d915eff514b8f3b4ef6932c6f113a88e1a07ba24b3c0a04ef547fb8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:754fc25ea38236e982c00f3b7863cd5be5d37ee20cb458ee56da3d99ce255082_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:9921943d6354f014e6c9d723b479d384da8827708fed076fe33924ab7b73125c_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:e6ce9a41e3459eb63d1cba772464f156f8310193c37da6e0f20b0be7f2bd1f3b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:07cecb266b131d35b03e13aac718f80cca805d721bfccb89239d32a30ee60d5f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:0e431261b489ebcf47d04fb1f78130ff1e651d41dd2b5cca65fd26bcbb141214_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:ab597e53d672a44d4ad4356e39691e1ae87523a4fccb82058a9031f4c8f4fe4f_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/metallb-rhel9-operator@sha256:e2d4a2104b0b236e218641af2a433c89421f000109003717df9df25a794f8912_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/nmstate-console-plugin-rhel8@sha256:25c4ce30e6a2d69a3e7f10ad7c5801921bd2e1ca5af84d2472709e4b455a27e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/nmstate-console-plugin-rhel8@sha256:30e5d88e1ee44159c9fee0effefe84371bf7250bfde4f9886a9c090eb7559b17_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/nmstate-console-plugin-rhel8@sha256:53fe5f4ee11ec1626e7b56567ed175bf4a131b3aa9531029c5899371731f93f4_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/nmstate-console-plugin-rhel8@sha256:82f4ada56771dfb7b6b65081d0745404ad464c7c223cd42ea392d040eeef14b2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cloud-event-proxy-rhel8@sha256:5adefe64dd438bbef12cfec97582c762ab6d70063cea328349a19b91eee94a6c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cloud-event-proxy-rhel8@sha256:6c99194985bbea419b05ac7d849489bb43ce9c05007c529b0847812c90251982_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cloud-event-proxy-rhel8@sha256:c50f0d3fdff38b8ce78967b276689cc32e4efe749ca19af9f17eb0dde672affc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-nfd-operator@sha256:0d93316577e6d89762574236c54e7f0da33c6b0414a91a92074ad1cd02e575ee_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-nfd-operator@sha256:21c88ebddda5d48811ae77054a1b67d319879a820a02188d5788efe2702c34ff_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-nfd-operator@sha256:6b3ea013f1f37dd5a4740a69d97e71d20acea6ece1b314f32acf2615acaf6d45_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-cluster-nfd-operator@sha256:fdbe21487e0681691918408abc18d4239e66c047ff27df2c24e517681f074ee5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:2587c9f8bbe953c056008b3f88dc2e0acb7c30bf23efa61e091583e922a25fdc_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:52e96810d73616e716d4fa4eb7de3d89c7665d728412da02b2904eaab9fcb898_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:8a20e5d567f64746b2ecc657f2b9cdb5daf6a5ae69ab10c6bee9cbabc3d4f458_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • +19 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider.

🔗 References (7)