Red Hat Security Advisory: Release of OpenShift Serverless 1.31.1
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-6481 — logback: A serialization vulnerability in logback receiver CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products119
- Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/eventing-istio-controller-rhel8@sha256:2b26accba46dec1e2a7b009a651adb96e31bbcb23110e2a7d5eeb2faf1df5a89_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/eventing-istio-controller-rhel8@sha256:ce30d09c74245cbb5ce0bd1e56c7890d5d1dab09f32de8bb9d95dc38bcefa49a_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/eventing-istio-controller-rhel8@sha256:e9e451554be91d262572c5bb551a86989f8e300d944b85c1ecc9b3ea557bbf05_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:a4938cee3f3314274638edea5022fd24ec5cc49c054286a7a36c56bf6e45d2dd_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:b1e19465c334ee323f43162aef6bbd165597633d359661c0904958e2878129bc_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:ffaaf64421c78a1b3f0bbd5d75435c156b9b09e3ac5614803c7c81ca7b2645ef_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/logic-swf-builder-rhel8@sha256:136cd272c25b4a385a308911e9c1e53606586d7f18e67b7daa87f0e3eef142b9_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/logic-swf-builder-rhel8@sha256:302189cc2ee74a14847380fb5f71187b0ff8299eddd2eb90fbe113f66238e68b_arm64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/logic-swf-builder-rhel8@sha256:c0413ebd128da64cd8e0ba46aedcbc680fac070b60446c0f03cb99ecdb980496_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8@sha256:0346b382d744d5a99092406a2639431e63d0cdbfe7674ad7beaa8e68cc5e7fc5_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8@sha256:55fc8d4388975c8df0ccd0b45eeef99bb65a3cc7fb5ba746ff07dbfb16e7404a_arm64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1-tech-preview/logic-swf-devmode-rhel8@sha256:c3fdef608969828ad1eae21d367f6a268715acd00991e108dd113381475b7a10_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/client-kn-rhel8@sha256:0dd6bf7f92fd7eea72a3968b27f55c08808e4687e2a65b6955fa1331a79d1d5d_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/client-kn-rhel8@sha256:700e95455c0c2514a4326ea2c1a597a58e4bbf67b656ecd2760e691df30380ad_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/client-kn-rhel8@sha256:e4410ad59242c54f1f53a58412baca79c0bee5efc3d8b40a403e2f6eead87718_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:1bad1e5889b07aa50871d74318668082e5f7fda8c09903f2eba198d226aa2e7c_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:dfacb95a77624c04ef789407ebd4283c88757881ea20bc341bd7d4c8d59f4754_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:e4fd565bc1e8bffbaa1bc16e62e56b0a66cab2065d2df49f4bd9b3c3154b4dc0_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-controller-rhel8@sha256:4afc2ba1d75f306319fedc00dbdb06b27e602bd6ef84b8397aefaebab32826db_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-controller-rhel8@sha256:659ad27b6570fc8c5666f9fa5ad2a3c47e683c68417a3bd487190af707788844_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-controller-rhel8@sha256:e9a6bdf36e9ef8a37932d7175277c6517bd0e85200f55acbe00d41028d43e4ba_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:2820f81589a86c6dab15c820d5e68e5a6d7d12469565033390d59ae3ec6ba31c_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:54cbeee83c053938e652f273dbc25855d24407787dffca84577bad55806a2a74_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:a002f3f229057b531e1350fef0101fff51057109d6af9440bcef43e6dfaa2bf5_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:42f051ed5e6e3f0e27ea1a448824d3190e1ab4205a814ff5c1918ca645119e47_ppc64le as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:a96dde60e638e2c7367ade552263f1b6a9c07e10672e0c125bf9befd48e19016_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:d25907fdbf530ec6102a87391c6a47e13becb781925d4f10b6834e1720ed6eec_amd64 as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-istio-controller-rhel8@sha256:2b26accba46dec1e2a7b009a651adb96e31bbcb23110e2a7d5eeb2faf1df5a89_s390x as a component of Red Hat OpenShift Serverless 1.31
- openshift-serverless-1/eventing-istio-controller-rhel8@sha256:ce30d09c74245cbb5ce0bd1e56c7890d5d1dab09f32de8bb9d95dc38bcefa49a_amd64 as a component of Red Hat OpenShift Serverless 1.31
- +89 more not shown
✅ Remediation
See the Red Hat OpenShift serverless 1.31 documentation at: https://access.redhat.com/documentation/en-us/red_hat_openshift_serverless/1.31 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: No mitigation is available for this flaw. Workaround: Update to the last version and check that client and server provide kex pseudo-algorithms indicating usage of the updated version of the protocol which is protected from the attack. If "[email protected]" is provided by clients and "[email protected]" is in the server's reply, no other steps are necessary. Disabling ciphers if necessary: If "[email protected]" is not provided by clients or "[email protected]" is absent in the server's reply, you can disable the following ciphers and HMACs as a workaround on RHEL-8 and RHEL-9: 1. [email protected] 2. [email protected] 3. [email protected] 4. [email protected] 5. [email protected] To do that through crypto-policies, one can apply a subpolicy with the following content: ``` cipher@SSH = -CHACHA20-POLY1305 ssh_etm = 0 ``` e.g., by putting these lines into `/etc/crypto-policies/policies/modules/CVE-2023-48795.pmod`, applying the resulting subpolicy with `update-crypto-policies --set $(update-crypto-policies --show):CVE-2023-48795` and restarting openssh server. One can verify that the changes are in effect by ensuring the ciphers listed above are missing from both `/etc/crypto-policies/back-ends/openssh.config` and `/etc/crypto-policies/back-ends/opensshserver.config`. For more details on using crypto-policies, please refer to https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening Note that this procedure does limit the interoperability of the host and is only suggested as a temporary mitigation until the issue is fully resolved with an update. For RHEL-7: We can recommend to use strict MACs and Ciphers on RHEL7 in both files /etc/ssh/ssh_config and /etc/ssh/sshd_config. Below strict set of Ciphers and MACs can be used as mitigation for RHEL 7. ``` Ciphers aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected] MACs [email protected],[email protected],hmac-sha2-256,hmac-sha2-512 ``` - For Openshift Container Platform 4: Please refer the KCS[1] document for verifying the fix in RHCOS. [1] https://access.redhat.com/solutions/7071748 Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:0843
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_serverless/1.31
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2252956
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0843.json