Red Hat Security Advisory: logging for Red Hat OpenShift security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28849 — follow-redirects: Possible credential leak
🎯 Affected products60
- RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-operator-bundle@sha256:d675e086761771ad5e70a3ddce30f96f0a91bd443de307a179b7c1342a7eb5a8_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:15ccd60db22636a9706c06702560e6b0e4f52cfedf0ad5a6c6057233dfda8171_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:615e4f439c7955af99bf6d6ee3593d2540fb244fb9c950d319a8a8b59b03ad26_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:7b9bbf6d009b516d21af7ccf84653a9f1140146952eca1b85484bdbe3690084d_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:d2e63036f6e3cdba49f8082e3e6e6f1a95f51a7166fb948dd41c1f52469f5a71_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-operator-bundle@sha256:46b194d96b141c0731a8ed35656b29ccb4caf63fa0f19055d74be066cc20590f_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:79603d1c244e06862e540a3c282d531017ac52d7021a9d9c97d6960738f6434d_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:7b71ddaeff2eee10f537bbd61861a92a7b1aa5b973c63dbb47536965db8bb531_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:a20b8524885e40707fcf70ef79e9a4245553bd4c3d6e080287504a3c8cbed333_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-proxy-rhel9@sha256:d79ab63de84c5b1f6da4878cb6a4bec03f7beb3b1fd48d4b0cad9c127b97ec3d_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:01554e429a76b38ff40df478aa0375049de42d3205ce409d20b3727944d6633e_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:260d4698651482296fb74dfcf711b8211dbb8515ae001f3976a4949f01783384_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:45260f2ea7388adf6baa5d70ba4bcaf8fc214379e63c6d1841f2190146225d7c_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch-rhel9-operator@sha256:75aea17b121c9a336ea54361df8d546fd938f46f0a7232cf0e533bc24d9d23ff_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:2b898191154fd0ae4a63b3a7ca25a6df6113165e5a240f29eaabd0efcde026de_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:95f51efbd2950ecce38ca2cfbbb380aaf07820263def9fae8613dae6210a2d12_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:ba5fd3974870a4fe10903672209e90e6c2d96c4287cc7d7e8461d62095de84be_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/elasticsearch6-rhel9@sha256:d7b469801b8b6516606eccac48cb54dd6cb9c09537bba55dc00fd8be337e9b47_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:1a54b9667621a03469b3f760f2fb6a9a1fca4d53163653fe9fc83e16f3cfff5b_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:271f5de065e6842fe381ccec36d97e0690488206cbfa58a3abd0f93ff58e5cd8_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:57cf91af5c4e460ec8efbbb7265f4678f383b637acc88045ee10fbc4d62c18e8_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:9fb4e3a4ca2e4af33c03c193c71ec11ad6b2048a846109e2042984ddd709ea6e_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:12fa9f69d9fdacd2ceb3cef7bd0ac09a67670d670c6f4820d6d2fb53354c9700_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:258f0f544ddeb993bdb5efe8a24f2b2c057d0a08f15935912931637ee594b1ea_arm64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:4c71401c0252ffa6be016903488b09ac3d0aea19f775783008bbdf598c2a3cc1_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:85786e40ccd23ce24f4b32483a5238562c03f8a65a683a551c278bdcd8cd3b9b_ppc64le as a component of RHOL 5.8 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:257f2085a55b76bbf538deec00f7bbd80a13164214c674b2dd1e98bcdb3f9dcb_s390x as a component of RHOL 5.8 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:9d3c09c7e8e26c95beeb5d7761f9d29fc0685b366ce61ae163000d78cebb23e3_amd64 as a component of RHOL 5.8 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:b628fdb3c66f387f3432c798829e8c7cf55ea8a86038079aa22dc1699e07b582_arm64 as a component of RHOL 5.8 for RHEL 9
- +30 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html For Red Hat OpenShift Logging 5.8, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.13/logging/cluster-logging-upgrading.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2024:1474
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2269576
- externalhttps://issues.redhat.com/browse/LOG-5044
- externalhttps://issues.redhat.com/browse/LOG-5171
- externalhttps://issues.redhat.com/browse/LOG-5201
- externalhttps://issues.redhat.com/browse/LOG-5240
- externalhttps://issues.redhat.com/browse/LOG-5250
- externalhttps://issues.redhat.com/browse/LOG-5270
- externalhttps://issues.redhat.com/browse/LOG-5272
- externalhttps://issues.redhat.com/browse/LOG-5274
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1474.json