RHSA-2024:0728MediumCVSS 5.3
Red Hat Security Advisory: Logging Subsystem 5.8.3 - Red Hat OpenShift
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests
🎯 Affected products60
- RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-operator-bundle@sha256:a864701d55e39b04803319d699244a5b3fffad80e821eca2fc2bc1ef220e91ac_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:0ad35ffc4f1ae0c7ed0db4c2eb2f7e0ac3479786fa80659afb9ca19d56a1ebc4_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:2ff48aff4001fcb582b405555348fc96e584b3b8cacd1514bcd7ca76fd9e720d_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:714e670785f1af783a8530ab0fa5657924b4d4e11ac27b83cae9c18a03576bb2_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:b8b97ab9a68104e6b5b39f92c49861569e0e81629b1511f99cd715e31b1261f7_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-operator-bundle@sha256:61589304df4c201923648ec7669a1e56fcfa115f6de0026cafb68038e266249e_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:3e407f82c9ac4e3eaf6d53d9a1910ab1bdc274acefb08de067a03a149304e55a_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:60c1ef42055b5aac996223e93e45d6322f96ba561e50ddadd456f6e22c060f26_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:b9667e7e4bfb467ac628e042aec1606c153a2675ae0023db7c5a97494b0e978b_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:cff2fbc124ffb82f97007ed11cb2ed579cdab269ae657988edd08b09ae151f4b_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:0761d9cd27ab367317c8d46ce78c8528b503a25426d84a84a6b1d591627c3627_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:49563e2447481af788afdcd63f2484b70246382da9e2ac8b8d98b72c3efcffb0_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:94f970194dfc9a0130a449182e1fb5a897abb254aa59358ff28ad62d18f96fa1_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:b3b75cbf7ee72577dbf338ef1eab793642777a24465af8a18d2f524e04872a5b_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:2a8c691d5337c0a47ddcc88597106675457b9fb79667d4865d5b82b2eb2a46ea_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:751b9b016625ffb3ec113b458a3eaf4b2fa5f0a01bb5c63d9e972ee16c974ca5_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:a89bf3d93e0a1f6c03c83eeadcaab4f47044feef4e08aa9f016d1a30048138d1_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:dbb0621339a2fa62631b7d00c8555aa358c699e39d80b9bce035902e9992bc0d_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:18120633d00e546502cbd9063de1b2e391ee1b80c0f774cd960acf5f72563f38_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:2b9430b4bc23c0c9290dcb9d8a8a4c1c20ba34ef2636977779a348c4aeee2dc7_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:995de53a8c1d6bdcb61b3281475503a2fa8fbad31ee9f991a4fb06d643ca7ae2_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:e8e1a5c5d6a730da6cf76e178cfb89458c97e6a83d5c61d6d35593b5aaa38600_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:12c4dc0bec37fbe89f7ca2d8b0f71519ddd28b1abce3a26c35b81a21803eb465_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:41de1d27dfb3e9833493ea965869a7adaf05a2f8d6e05523f445846a2ed9b3c8_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:4e3e28c9c1ebb9912ac05d44c09917d6a23e82696b835bb81cb3c874d4d94bd0_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:5ee0c39a1f5163e941fd6d94260cfa1b6c71d98777612240663749b629249c53_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:13b15e6259506ca5539c3d7ab28f9412144e7032069b367eb24bd9959178063c_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:7f81d334b3d4da0f5e08d7952d5caca5e30239b4d0bc9f9e6b8a6809b089f396_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:8ebb29ef8e70efca1fe458632e19a8378955a83f1ea26d27bce85327f25390fb_s390x as a component of RHOL 5.8 for RHEL 9
- +30 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is available for this flaw.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2024:0728
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253330
- externalhttps://issues.redhat.com/browse/LOG-4822
- externalhttps://issues.redhat.com/browse/LOG-4893
- externalhttps://issues.redhat.com/browse/LOG-4962
- externalhttps://issues.redhat.com/browse/LOG-4963
- externalhttps://issues.redhat.com/browse/LOG-4969
- externalhttps://issues.redhat.com/browse/OU-319
- externalhttps://issues.redhat.com/browse/OU-320
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0728.json