RHSA-2023:7703HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Pipelines 1.10.6 release and security update

Published
December 7, 2023
Last Modified
September 21, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🎯 Affected products97

  • OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:55e9c7b4b20b7fb149b72b8cc5651f5fe935bd9f25c9694bce380d356a860b1a_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:85fdb3c014f3dfee1023cac40da2afa86bd67a550df26e67ac0e261ad4542bfb_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:8fefa9f58b08005d8f9f11c722d220062766ee08f96d45151909adb09abda056_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-chains-controller-rhel8@sha256:c920fe3b1db3381209799acf54d5c5d3c195376984584a34a6b5944619285a39_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:382c0866f55be9faa809433525c08c285869d906f2a929be564e0ed9bbaeb35c_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:70071155cf42e2684aee45050bdb853ea945706b09a3d4252fb6d372a66925c7_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:83fb2abbada2977e28f0f602d71adb8c34cd4f62bb7cc7a39a50e5aa2de281e9_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-cli-tkn-rhel8@sha256:f106128a15deb5d68bd5a4507bb4ff6c05fd7dc821f14bdc5c83715bc73afbd8_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:856412ba225b33f533cb1646870b675132171a75df6c28af6145a9b5ed61aafd_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:876abbb7217bdfccd53d47b71facb05113238dd416bd2736290a1d7dcf1f4f07_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:a007e4edd1aa4135ff28b6eace7063a6ff6d1a367aa8ba53a4813ed44e21f0c0_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-controller-rhel8@sha256:c4691035533a5a74ae233b9efe85f69217495ca263fa7fd89f31a83461bf83e3_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:4f7fef7e1240e672915acf2d58ff5bf8d2ed746c5c225d1b25f930aeb92c4e98_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:6bc699cf9fc045ab8387667510964b18265f8530d7662312310449c95ded5995_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:a19d7afc74a0e21840c1a03c1ae8686581633f9784d89e9a70867b3145b679c4_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-entrypoint-rhel8@sha256:f52bbf4f3a978b0a6ae7bc3c5eb0634d4ee33b5daf3a4f3fa9db1b55e6afccc1_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-git-init-rhel8@sha256:2c6590ba54942fdc3e2aae7d7ec7e53c4057ed464f996c8fe80fe742a6313349_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-git-init-rhel8@sha256:d6cf30ecc2c869a290b2019c762ce7d7de4877f02e453bb144cca7a5f520bff6_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-git-init-rhel8@sha256:f8c3e9e84b3bbd5e10edba8f6cc8868c740bcbca47c0e7f9d650b84fd69e8f4d_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-git-init-rhel8@sha256:fcf71347e6d3517a41ffbf30f3cdc2c71e6dc43bf75527abe37d8aa2c8951326_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:32e6f78a626f347bc7682ff40c3266fdeaef79b29016331514c845fa7c073734_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:578c3b66cb78953b4641676d2babbfa19093abf35ee4f859089b8f8ef6f1bb5a_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:6f37fa6c5dd5723fa6d1916adb34cb16a5851cf89b09eb176d1140b09f61a67a_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-api-rhel8@sha256:da2e577dab4fbe30a9242972970a3f1ea52ccd44480a2205a5e4f033a9728017_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:6084668102f3a6fad342a031b6ca0e3f32efa45f818603be804e9186846523f3_ppc64le as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:904ae8a15cbda8df133632b9a9d34947dad541a64c3a6e64c2b5442f8c250a3b_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:bb8dd2af0b4c223878522730f8b42e944f73226c114b2c4779401ff40c45e56b_amd64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:d264311d80337877f78627a32ef53dd1ca1552ddf4aae5fda7cd778869a1f243_arm64 as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • openshift-pipelines/pipelines-hub-ui-rhel8@sha256:0892a6539d28ebcbb8c5b576105f3b16f42c966062400fd74ca8e9112ee889f3_s390x as a component of OpenShift Pipelines version 1.10 for RHEL 8
  • +67 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Users are strongly urged to update their software as soon as fixes are available. There are several mitigation approaches for this flaw. 1. If circumstances permit, users may disable http2 endpoints to circumvent the flaw altogether until a fix is available. 2. IP-based blocking or flood protection and rate control tools may be used at network endpoints to filter incoming traffic. 3. Several package specific mitigations are also available. a. nginx: https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ b. netty: https://github.com/netty/netty/security/advisories/GHSA-xpw8-rcwv-8f8p c. haproxy: https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487 d. nghttp2: https://github.com/nghttp2/nghttp2/security/advisories/GHSA-vx74-f528-fxqg e. golang: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2.

🔗 References (7)