Red Hat Security Advisory: OpenShift Container Platform 4.15.11 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-31463 — ironic-image: Unauthenticated local access to Ironic API
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:217b4753a8444780cf5d952987353af77bbdda53d953a3be480b5824266d70f3_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:a86c6b20ae4c33a8aa95f576fc82f84dbd386342a75023822ee7b0595ae995eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:b06d6599f0cc9ad80552aaaaeac2dc8330bba7c0cb63171247709336e4a0c3e6_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:bd87e481fb8c12192ece010be9af9bbcd8165e88a84401e108897fd0fea7f48e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:2f1d0079b6a100866055b2b7ba7c5ce8c29dc554455d29751191b59a0412b41b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:40c8106debb597f5a4782e7c2d8bce94a5f5f10b6130860d8259eb8f44177fb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:bae8035c05d095e84c62efcab6202330a98493cab03e091c81a0b792afb5672c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:e94abd8054d410114c3ad57fa678003c036a2ea70c0d43b0dd6c8bde20c5b5c8_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:23e977f451a38168f6f8da74fd99255d6d931559ebc8ec104560b0c9256d2174_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:88aad174846b2c6bfc4ff76d88a7efa47355e30995cf62be117f43773cb3158f_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:c556a9d1b299e8518246ad7f70f45747c12d56e72c9740ef741400b91593d504_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:feb7774b774e84a0e65a27d46bf1eb58a19be2b81e96d1f5f3725d449c7da5e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:4462f13fe10b030e2bdeb749f2c5112089dc85010ab5153438c5b79edef124c0_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:53baafb9ea6d786fb1bc2e454d60245ee8c7bebbf7aa73d9680bdf69fb0c1223_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:5ca6014aaa75de5eb73562fa2d84b44af110c97cad46989ad5e5b61ce05564e8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:b3738775f43db1a1ceffd9a4c8f79d1a8dcf46e7fc0c6c4273e11bc510c7b5ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:7ddea8980b371ad3674600a20a80968947538b1c3378de2ba97a9b2040d3a913_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:88ef0addac6e9b94a0e67b4bb273d90e97aa3764fdf68acb7c87690d60f3e418_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:8c9dc6d0fbad3bd03cb27db0d01ffe335bbabcb50d1cefb5959a597151bec804_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:9b8ca585cf332f1e1d00235cafc0f8d8958412619069031af6e03e23587fbb78_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:6365bb9f7639852fd201bb4f3f065b86273ba0d6c244444c41c725d3564f3739_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:848b5047b36748987e3f9858ee374363f67dd85ea4318a0338f85dc0538b151e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:bd2cde65ab97165c492ff9529f406065ffb56cb36194dfbddff6b2cb58ab13c3_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:f50fb1faa35338d55ce68e661a89d66ca30c8bc854814272a653dac8cfd7e5ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:0778c5faca4bb41a721e9e97ff4e303652af5c2e366295a35437e482adc7de77_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:20ec2d6e9f925c7ffe257b684dba99cc911bb676079355acc452dc22274169e4_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:2b03a49ba90b7aac9107c3cf1bd2028f2ccff090df9c2ac6aeea0a3fcf841935_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:2bcb61a28b035448b05fc369d670bfdb7ecc7103a73b112cfe7e8c794e8f5dd2_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-agent-installer-api-server-rhel8@sha256:6c57f815da953a4fd2c738681fddbd757a29798cbb44e73208d19a60827ceae8_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:54bf0a80b3bbace603d824ae5dac687e3bd7591ed4f629ce70adb8a01654585c (For s390x architecture) The image digest is sha256:d58943ac32b575a9c99ffd4e1a9f73185fe9892c16f54800ee4b6271068892cb (For ppc64le architecture) The image digest is sha256:6852d42cdd8d8484818731ead5fb23e97f0112f1b697421fa119f2b366480e0f (For aarch64 architecture) The image digest is sha256:d3f309145d440c2f66d9d5d499f2e3fac34e3050312ef16722e8ba0f9060cc9c All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Below are two mitigations for this vulnerability: 1. Switch to using unix sockets for traffic between HTTPD and Ironic/Inspector (recommended). Set the variables IRONIC_PRIVATE_PORT and IRONIC_INSPECTOR_PRIVATE_PORT to the value unix. OR 2. Temporarily stop using the reverse proxy mode (set IRONIC_REVERSE_PROXY_SETUP and INSPECTOR_REVERSE_PROXY_SETUP to false).
🔗 References (40)
- selfhttps://access.redhat.com/errata/RHSA-2024:2068
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275847
- externalhttps://issues.redhat.com/browse/OCPBUGS-22926
- externalhttps://issues.redhat.com/browse/OCPBUGS-27948
- externalhttps://issues.redhat.com/browse/OCPBUGS-29092
- externalhttps://issues.redhat.com/browse/OCPBUGS-30970
- externalhttps://issues.redhat.com/browse/OCPBUGS-31045
- externalhttps://issues.redhat.com/browse/OCPBUGS-31324
- externalhttps://issues.redhat.com/browse/OCPBUGS-31641
- externalhttps://issues.redhat.com/browse/OCPBUGS-31686
- externalhttps://issues.redhat.com/browse/OCPBUGS-31802
- externalhttps://issues.redhat.com/browse/OCPBUGS-31806
- externalhttps://issues.redhat.com/browse/OCPBUGS-31811
- externalhttps://issues.redhat.com/browse/OCPBUGS-31820
- externalhttps://issues.redhat.com/browse/OCPBUGS-31830
- externalhttps://issues.redhat.com/browse/OCPBUGS-31839
- externalhttps://issues.redhat.com/browse/OCPBUGS-31842
- externalhttps://issues.redhat.com/browse/OCPBUGS-31924
- externalhttps://issues.redhat.com/browse/OCPBUGS-32024
- externalhttps://issues.redhat.com/browse/OCPBUGS-32093
- externalhttps://issues.redhat.com/browse/OCPBUGS-32097
- externalhttps://issues.redhat.com/browse/OCPBUGS-32114
- externalhttps://issues.redhat.com/browse/OCPBUGS-32164
- externalhttps://issues.redhat.com/browse/OCPBUGS-32173
- externalhttps://issues.redhat.com/browse/OCPBUGS-32191
- externalhttps://issues.redhat.com/browse/OCPBUGS-32246
- externalhttps://issues.redhat.com/browse/OCPBUGS-32299
- externalhttps://issues.redhat.com/browse/OCPBUGS-32311
- externalhttps://issues.redhat.com/browse/OCPBUGS-32340
- externalhttps://issues.redhat.com/browse/OCPBUGS-32355
- externalhttps://issues.redhat.com/browse/OCPBUGS-32357
- externalhttps://issues.redhat.com/browse/OCPBUGS-32396
- externalhttps://issues.redhat.com/browse/OCPBUGS-32399
- externalhttps://issues.redhat.com/browse/OCPBUGS-32414
- externalhttps://issues.redhat.com/browse/OCPBUGS-32435
- externalhttps://issues.redhat.com/browse/OCPBUGS-32498
- externalhttps://issues.redhat.com/browse/OCPBUGS-32518
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2068.json