RHSA-2024:1812MediumCVSS 7.5

Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.12.1-376 Bug Fixes

Published
April 15, 2024
Last Modified
September 18, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2024-28180 — jose-go: improper handling of highly compressed data

🎯 Affected products6

  • OpenShift Custom Metrics Autoscaler 2
  • custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
  • custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8@sha256:902b54fc0dad9ceefa86752585e37788c47ae08423109b8c572966a56e29de18_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
  • custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
  • custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:4c2b8009baf3e0424a3504f9bc49fc9342608fcd350afb2fbff2c9568e5f68da_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
  • custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8@sha256:af913191f4a7273f29545f64012cea08e2c35296d4e3e3b10c8358feb4c425bd_amd64 as a component of OpenShift Custom Metrics Autoscaler 2

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is available for this flaw. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)