Red Hat Security Advisory: OpenShift Container Platform 4.14.9 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics
🎯 Affected products142
- Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:26e22b7e19196816a899f0ce25d080d1d542bd55c9e531af2d0aa45e2328b245_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:749f5f9634ede2201b27d3ae7d741747de83fcfdafec5cfa658dbc66b8ee752e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:973f5eae3ec1fcfa775c9e659cab5669bcad165bae477ecfafc131b4651121c8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:adef3d58b036a4af6d11914c4348af235a8180b0e182c9968c7ccbbfe1bb747f_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:0c1d7bdd6abc0906a5cace38f728e204ab16a2275258a796436cf430ca841c9b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:a607ecd52f1c831dd32e78bee2ff622022066b3ad64730f0bb8ae329e8e48b7b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:eb71962184dc866303fde9e37d612510b9a9745fd10b092f127029fa560848b6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:fba289d2ff20df2bfe38aa58fa3e491bbecf09e90e96b3c9b8c38f786dc2efb8_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:074c88501eb36be165626f52fa0194a06a6b8279f9374d96308aeab32ed5ce0e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:2bc0052364a8bba676ae32b9b564563d59a4de788907af1e6727653a17799c46_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:77393e2c8698b35b4d5f8bcad24f5c285a3b3dfee75a736bebea304ea9d39d5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:b994aa5e8df6a93cb87b7f1019ea92a69a59968f3781a6e5cf478fea56991512_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:02eb8ae8f8729f863cfb32926258d2fd6c39f1a821b76c0233175d4fbe5d8f0c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:1f2c783f8e4c7e616c868192b79666f1632d9c478fd451623adb6dfc1406746e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:7240113568fa6a9f7241a10cff9a31346466fa7e5b05a99f8f4389c00e710093_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a4d690f1e2485d62accd5b579aa7cb451a23ca5062f89f3cc3a6922177748f4b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:58f5d62705884b9a958ea1018b4d604425d5e8d9e8783cd0821438323bdf5b33_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:6066d1028bdcd04afe5427d6e7582e785f9c0a3567bc142cdc7cdc2879ddf5c9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:8f193ad2f2ac8efc226f3651b88978089d483e1292af630c8e2ad0ca8cceb7fd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:9b758ea84d81270bd76b4651624bfa27c96ca01d801d447d2e8017b22c326374_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:2948b0781e7434e2f648120cedffa16b7c32c768eb10fff02572461c6dc9fedc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:55a47120ad2d3ed13f0e4b71633c5cf830e1409679f4ab8681e1733748716463_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:753ecf3d042f52de5425f6f1254c4a80bc05cd4d8a451904df2986b67c30bfdc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-baremetal-installer-rhel8@sha256:ca45793ab4e049f57d78daee44ca9664e24710ba28611c94a43f3f7b63c0336e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:6673bdfd0dfaf3d44f0105ad5c54433f70c4ee0b8a6e769340e6925f5da1f970_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:a64371af1873fc7206e630bb6e28da909d1fc9887798a26c47ae50ca8da0f7c1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:b567466978189f4906079ce82138fc8fec2c46cc6684f57a8e9a5baf324e2cc0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli-artifacts@sha256:cde696e27696aabb716b1af5431c16a9b735f9a007b18ff0423353946ee472b2_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-cli@sha256:0cf6a369359fac5ad5e6933b9bd5f9aa224bc79832474bf0dda6fbbd604a9ed6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +112 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:f5eaf0248779a0478cfd83f055d56dc7d755937800a68ad55f6047c503977c44 (For s390x architecture) The image digest is sha256:f4c1e8cae3c214140146c34d49830f9765f42e7d2b31251970fd26dc8652d4fb (For ppc64le architecture) The image digest is sha256:aaa152edd2e5c5b4f1d7725024b710c596eafd28907a645817e62a629503388b (For aarch64 architecture) The image digest is sha256:5077e66818151136b10f92f81b88183f5ccb69d837847d2f5b3a2020a96fd873 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2024:0204
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://issues.redhat.com/browse/OCPBUGS-19431
- externalhttps://issues.redhat.com/browse/OCPBUGS-22360
- externalhttps://issues.redhat.com/browse/OCPBUGS-22788
- externalhttps://issues.redhat.com/browse/OCPBUGS-22895
- externalhttps://issues.redhat.com/browse/OCPBUGS-23936
- externalhttps://issues.redhat.com/browse/OCPBUGS-24037
- externalhttps://issues.redhat.com/browse/OCPBUGS-24640
- externalhttps://issues.redhat.com/browse/OCPBUGS-25595
- externalhttps://issues.redhat.com/browse/OCPBUGS-25804
- externalhttps://issues.redhat.com/browse/OCPBUGS-25997
- externalhttps://issues.redhat.com/browse/OCPBUGS-26006
- externalhttps://issues.redhat.com/browse/OCPBUGS-26044
- externalhttps://issues.redhat.com/browse/OCPBUGS-26065
- externalhttps://issues.redhat.com/browse/OCPBUGS-26171
- externalhttps://issues.redhat.com/browse/OCPBUGS-26207
- externalhttps://issues.redhat.com/browse/OCPBUGS-26214
- externalhttps://issues.redhat.com/browse/OCPBUGS-26421
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0204.json