RHSA-2024:2062HighCVSS 7.5
Red Hat Security Advisory: Service Telemetry Framework 1.5.4 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
🎯 Affected products8
- Service Telemetry Framework 1.5 for RHEL 8
- stf/prometheus-webhook-snmp-rhel8@sha256:bd5bb9df713346ea63547b57d208231373fce446cce33295883338950c1a08f7_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/service-telemetry-operator-bundle@sha256:16ad4c03174a40251fda2e2e4dae6f0a346735f0265450a9416702115d228c89_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/service-telemetry-rhel8-operator@sha256:abcd7c934bcdbb6a69d995c88f31e47e1be5668d2fa330fd3985a643162ef936_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/sg-bridge-rhel8@sha256:8cfb3292bde7dd69ca5665df2e47d72e22961600c48158a2ec560dbc909e79cb_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/sg-core-rhel8@sha256:4181039f97efd2492392dc0255a2656e80afc33ff84edf193c2add3573dc08ab_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/smart-gateway-operator-bundle@sha256:5c3e0722b0f8ebc278ef7f7d0b7a95732bb5dddfa5a2e0feb8d036206b0e5661_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
- stf/smart-gateway-rhel8-operator@sha256:ba817dcbf027c1ccdcadbb0b627eadd97c69955f800acb1ca9bcc758d952533f_amd64 as a component of Service Telemetry Framework 1.5 for RHEL 8
✅ Remediation
The Service Telemetry Framework container image provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References). Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.