Red Hat Security Advisory: new container image: rhceph-5.3
🔗 CVE IDs covered (9)
📋 Description
CVE-2022-23498 — grafana: Use of Cache Containing Sensitive Information CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2023-0056 — haproxy: segfault DoS CVE-2023-0507 — grafana: cross site scripting CVE-2023-0594 — grafana: cross site scripting CVE-2023-1387 — grafana: JWT token leak to data source CVE-2023-22462 — grafana: stored XSS vulnerability affecting the core plugin "Text" CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters CVE-2023-25725 — haproxy: request smuggling attack in HTTP/1 header parsing
🎯 Affected products16
- Red Hat Ceph Storage 5.3 Tools
- rhceph/keepalived-rhel8@sha256:6a75187c09c4c29565a936b67314d37fa34cabe0902e5a70deea731ddcee59a2_s390x as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/keepalived-rhel8@sha256:a3271d3fe7f918a59f96c32fde709b66c9dc5f6d482b5881ca5322a3d701de58_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/keepalived-rhel8@sha256:e39e1ff87d78a154a98bc60f4002ced54758aa1cbbe1a03d57b3141e046eecad_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-5-dashboard-rhel8@sha256:5eeace779a37893bfe8f526be9dcfbcf6131af8009cc09d8c04c6a30adf23832_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-5-dashboard-rhel8@sha256:6862d889c99ed5652b877660533056d539918e3362a25fea0fb53abe7de23a32_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-5-dashboard-rhel8@sha256:cbcf2ca9ef81e45796ece23783c282d0313d4a6813a086122466af3f0d3b6088_s390x as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-5-rhel8@sha256:10f9c1198dda12709ad7d67f9cb270370eca4f882ef00f40586d5b0acbc8190b_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-5-rhel8@sha256:51d3d740a3b063e07a6054142d28bb512af3772201c2233f8e14be5e3d4f6f05_s390x as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-5-rhel8@sha256:e0d758ac81cdc23c8a03ebc7832158ffe53a8cab9b2f5f18dfac0bc0147b0f6f_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-haproxy-rhel8@sha256:04682c5e2b75cebaf5bd57c9f2c9375361869aa3b7e2e8795a548b7f872327db_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-haproxy-rhel8@sha256:663c2136462c821cafff78ebe1fd993308834358b1241eb7a8c1c440e3057935_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/rhceph-haproxy-rhel8@sha256:88f02f1bba0d7698a1848ad011c418bdaaa97b9095f5d5d5b7fdda48869c87a2_s390x as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/snmp-notifier-rhel8@sha256:031ef712e4211d539514d5c5ce447515f5711af4e6b679e758352942b8b2d709_s390x as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/snmp-notifier-rhel8@sha256:ab41dff414825b28512047407bb4bdf7bfa67c02f783c2469712f54a24a5d167_ppc64le as a component of Red Hat Ceph Storage 5.3 Tools
- rhceph/snmp-notifier-rhel8@sha256:d7334b7d095562b8fd7d93b17bc5a9f4b2788ed553148bb8bad9ab0a2bba0be9_amd64 as a component of Red Hat Ceph Storage 5.3 Tools
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 and https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5/html-single/upgrade_guide/index For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: To mitigate the vulnerability, disable the data source query caching for all data sources. Workaround: Applying the Content-Security-Policy shipped with Grafana would block inline scripts from executing and would mitigate this. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:0746
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2160808
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164936
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168038
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186322
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256938
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0746.json