RHSA-2024:0041CriticalCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.0 bug fix and security update

Published
June 27, 2024
Last Modified
August 22, 2026

🔗 CVE IDs covered (17)

📋 Description

CVE-2019-25210 — helm: shows secrets with --dry-run option in clear text CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45289 — golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-0874 — coredns: CD bit response is cached and served later CVE-2024-22189 — quic-go: memory exhaustion attack against QUIC's connection ID mechanism CVE-2024-24783 — golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm CVE-2024-24784 — golang: net/mail: comments in display names are incorrectly handled CVE-2024-24785 — golang: html/template: errors returned from MarshalJSON methods may break template escaping CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28110 — cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials CVE-2024-28176 — jose: resource exhaustion CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-28849 — follow-redirects: Possible credential leak CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:361f5b11d099da2ea6841382f8a5710cfad011e2d4aebb07f8a7dbcc7d51a0fa_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:5668f00f71bfceb7bb7966d7a9f432f2193436bbfa1ebcefaadfe2f48a2be55b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:f530d974271b34ddfb729afe0ac7a4547ddcc810876c08f70206a066cff3ba39_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/aws-kms-encryption-provider-rhel9@sha256:f7fe23f34ac9a131b0196861cf5ac8bb4851ff178a37ce9b44a128a939f05b0f_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:02bcd702b111974652b114099171afef4f269353aa7b36eae8af403f2dbfb8e6_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:84b27607bc9958aba571d885205407ddfa37873c98be07249f26c461580f3ce6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:c46d221b9b58ea30986a7a28b7d6fa50a8010fc1302bb32bf7def015150d7f91_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/azure-kms-encryption-provider-rhel9@sha256:e29c1cf827ee8834c8d87d5661b70b7331a5d78456440478e4a31314ae96433a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:bc5f4b6565d37bd875cdb42e95372128231218fb8741f640b09565d9dcea2cb1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:c4df84685fcf1bcc4a06e142f2c88f07536b1195a9ca287894bb8812ca22a7bb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:cc91cec063e59e647352e4bdd64e82dbb2fe829f26f8f3b3cc8caa05fd190992_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/cloud-network-config-controller-rhel9@sha256:ee7118a26193f02cb99292f4ccb52dc3bb542df81c923c43f147c66155fc3e5f_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:b70fe2f9204510f55db978760c585e0b837d94f18f9fa9ef975c8a3a6b5f4aa3_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:bfa0eb975a9e28c9ad40cd92b0ffecd78227d434d0ecd1a42f8d87c238117045_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:cc2ebb4057f5aa31e9c028a1084a6d001c8327ce79f89046db8727007d740de8_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/container-networking-plugins-microshift-rhel9@sha256:f1776c5c20353bd9ed42b8c118271d4652cd8e2e84b80aeb1896a763ea24c2fe_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:406a0ef3561e737c3c6a5eb334aad8427fe04f53683d92516ff44289c0cbfe85_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:bb4a91aa88e353a1f856dbaffff2e5024883caf0e473c1f697e2ded7da1e3eae_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:c53469f1058565d37c23d3902d275a614756d822a14f09dc0e9d6f90735c11e7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/driver-toolkit-rhel9@sha256:dde3cd6a75d865a476aa7e1cab6fa8d97742401e87e0d514f3042c3a881e301f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:088c4baa9b12b65e72f6d5201b84b31b6dab5ffb6f4e9dfcec979587b51c20a7_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:0a57c4febc329df33c335c1df724f89963d7c08df70acf9ea36472df436cafde_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:476d419f3e57548b58f62712e3994b6e6d4a6ca45c5a462f71b7b8e5f137a208_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/egress-router-cni-rhel9@sha256:cfbf036066f0e599dd86594764fae9dd6a0997ecc361b36e7e09af8c2c8c3995_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:4b3aa166dea307a865e9a71a796980a859eea4a1dc0a62b1e33b4810fe96ed13_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:8c1f690970ce6e1457238c76bcee59f83c50c02a9b07b2ee9baca4fcee819fb0_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:be56a2bfae2b849e8e749ae83a9ba8b8ab9ed3ecfc979c2c37cb75712de0d370_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kube-metrics-server-rhel9@sha256:d7595b738ec788913e4ccf2a1dd448a831ae7289a79da6258f04f8378831f7eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • openshift4/kubevirt-csi-driver-rhel9@sha256:21002184f9e03430cd52fd14c96c8c27b1c4674b87c6197262bd9a0b70ae08f9_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:3717338045df06e31effea46761b2c7e90f543cc4f00547af8158dd6aea868c3 (For s390x architecture) The image digest is sha256:f02384fd3022a53fa24e142c3d8eb51547f566611a9dd560d5bfeabab1e578da (For ppc64le architecture) The image digest is sha256:500926479acad10193dbf6ea3944e23b92ff004bcf7bfb7e85728f1b8cffe2b2 (For aarch64 architecture) The image digest is sha256:817126345d1ee68397634303571632c5cc8938cd4d59f940803ab38d8e6799e3 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (1339)