Red Hat Security Advisory: logging for Red Hat OpenShift security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products64
- RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-operator-bundle@sha256:32c00839a9feaf7d3a3365a62562f0348fc3d72f9c8052616539d0161d88a574_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:7de6d4e6f4184374c1f4194897924157b05db17909844eb483fea81fc9830ab5_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:9048cfa21f05513e19b19913a0553b1629dbfe8970b70f115781fc5c7530d988_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:a39de32fabd2deec35506897b871caf594e061926032f91140197ae0d362c1eb_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/cluster-logging-rhel8-operator@sha256:d147ced8dea6ba59102e9e0cd87078d97f4f5e7f9577da8b7739efc447a49b6b_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-operator-bundle@sha256:f487d91e2df318c6d7fcbafdbde8304c4e78341f71ed91c7749ffdc41e13ed94_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:1672439fe0725842fd7dfaed85acaa917e5e11fc4b4cbd2ee47f63247fe6df83_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:65650d796dc4073b4be23d79e026f8312315200396d98a59f9819c1b3f68563f_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:d36a834c264b07c8e3a2c2c710bfa92aae08517a12bf1c82b666b2eee169c11a_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-proxy-rhel8@sha256:fd7654b10bdd6ead25e848bff1138d1a7296394e32931ab69b61699ef58fca80_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:2ad65674ad1965be9af734e1c303c8fc6ce037b53dc544166af34580b90a3eaf_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:4dbcc6f81e016c406245fb3b703aff0707a0aaa3b322c25f814e5d750901d6f0_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:6f6eff31c7ce0b74af15f3fe1bbc288c384be0021f08ae773cf0a428b99aaf20_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch-rhel8-operator@sha256:8678d448b67b9fa0ab07a582c4920754711b5de998c5013a772d5c4834049b56_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:3ea949120cf831fdd3d17ab0db9ecdc3285bcc1b35513810aab87d277f04dd22_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:4c14e3ecd699fb8695bbaad85e496de0b6442ffa44d3eac4f1759bdc076bb169_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:e17559447795c40edb0185b580fe5d72d90057da294dbd75ec571e2ff2c549a7_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/elasticsearch6-rhel8@sha256:efa83744b53aab35f20e0a963e19f5ee4d15460f55e2b10536e71591919f55e1_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:3df82df2f0f270db2fdc11309f6929e453a7bf404e793e44a6b846fc4adfa4ef_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:3f0634aec90df3c4b4590a74e503d974ac90a356bc7031c8a6257cee13ab89e7_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:b057d736376423a5c35ddd69b40602b6bb833e2c2953eea5c33e96b94b06a239_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/eventrouter-rhel8@sha256:f30221a22d9863f3fd88828733e2ffa81dc85da886b46fb3aa4324288f58a2ab_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:03e312047e344331b6abe9c720841cbe536ebae00613c44b53c1e9570e4e8c40_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:5941d872aef1415286230ee03fe2f42ca2cb799568c2fa3e4f5ae99ba3051a62_s390x as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:715cbbcb0eba7dfbf8a2f53853085ac2ecbf571c694a9f864d0b2230fd8db09e_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/fluentd-rhel8@sha256:b2901141382b34c9a7b83714c4e91b092a01c65b10c60fb0f4f4c951743ed570_arm64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:2ee16c577d1d9496b7439caba7cc33c8001e55292b46e756fb0f510f46bca0a0_ppc64le as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:3432c849ec8fe1ddf5e02ffbd69202c2354467f735d749cf1358d4308f984510_amd64 as a component of RHOL 5.7 for RHEL 8
- openshift-logging/kibana6-rhel8@sha256:5b6290114350d5e397feb4229fafacf6dedf182512610ddcfc96297e7ef7f13c_arm64 as a component of RHOL 5.7 for RHEL 8
- +34 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html For Red Hat OpenShift Logging 5.7, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.11/logging/cluster-logging-upgrading.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:1508
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://issues.redhat.com/browse/LOG-5172
- externalhttps://issues.redhat.com/browse/LOG-5202
- externalhttps://issues.redhat.com/browse/LOG-5241
- externalhttps://issues.redhat.com/browse/LOG-5251
- externalhttps://issues.redhat.com/browse/LOG-5275
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1508.json