Red Hat Security Advisory: OpenShift Container Platform 4.14.11 security and extras update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products175
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:408d3e7d4cf9f4767316fd403866c9153023421b3a4d258a0f16081b5c254799_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:cd0a806f21ac567093e073066e0d459bade3d54a7506a26cd16c833b32e8a89c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-event-proxy-rhel8@sha256:e39d2109a425baae94e59c57c86b12b9ce45070cf9dd05fcb0def2f293005bda_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:650c56a6e007a1de1ff193006ede4319b71d08b4e95d4116186116eebc845f6d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:99ec12347648606f243239ec249e92e418d42bfcd2f8e85bf794f1360ece3a9d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:9bc52bccc2f31061f7b6d79f22b60a060d92d4e88184d50aa7bf54aacd721b78_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/frr-rhel9@sha256:e3d81d3d78a4772219b9c9659ab9b321609428fe5885fb16dde24fbca734566a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:66d7020bb2adcb2bb09b52f9ae227ecae9e03970d3c1d7f0f1826acf42db4b68_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:da6d0b15b26f466f52cf8d6aeae496bb186b1a7bd95e1dbafe013c48c7ca87af_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:e6e272c81ba2adc7ddda1e7efdfa63bc46fd035a1081b33acb51cfaa6783404a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9-operator@sha256:f0992ec6b5814e7255daa10ccb6cfde3dfc576eb64a205f0b61bc57cc346e1c6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:0a4146e656997ae3bc53d5dd66bb0437f0fcb406216cd20819ec39d0dbd19fe8_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:21e47fb54587dcf8eace41afd6103e163046ccc9d9a656057f2b6981b024cd48_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:b51a4af63c2a7c1cca6a67ff4aafe0e8e16c977b7a1fcc95c3507062cc22e1b9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ingress-node-firewall-rhel9@sha256:ce6d765a708364f77d2db0512c86736cdcf224926a79a9aaf073887cc2512303_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:172741181fe22c603f59c425a14bdd311a0ba2771790ea4e765275e0e9bd1210_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:2c8413fc76d2a59c14e6f045f2fa488bb75a903acb2641753e5e7be44c9c1b7f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:2cf96b39180c3ca9febc7f657603da18e665c6575ff3c3c43a0c88d86c322fd6_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:8f16c2665e53a19a44734ac69a44262f069afa176255c733289c96bcddc12ae8_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:4dec1a577025fbd5307c27d24f858f7e54dbbf512dfb6f6679d9e5e1f3ec27fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:a51c36274da9b1af0f09a1b83a060f4b340ef2fb07364548c4ec74b205ceadda_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:cad128d352e4619682d069485d02f6e038a6b50731213692458038992eea3add_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9-operator@sha256:ed4830a87d29055e1d3d9c192bcedfa250e33243914b7377c07336b14aa34140_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:3697dcdd3cdff10dda4b12124667cf41b7f1883c650dd75fa108b036a3a6c96f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:3cabede7fe3c37dc642932224f71c70d584d6ce0296fcea40fdb12aeca3beceb_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:b7db5a4d8e45ee9e66dee98025a05911771915feab3cc8f727606adaf9676dad_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/metallb-rhel9@sha256:f5ed91968f48250006da9b341af790cb14d4d54736bb301fcfceeca5fc766291_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:07313e6dffd09ce622babde63976bb386fdd70ede756eb5590980a5b72634d27_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/nmstate-console-plugin-rhel8@sha256:12e63e51f20a93cc9b88b5da9a36d41c1e6c438b4bb815b14e870107bd09c997_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +145 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:0641
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-26237
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0641.json