Red Hat Security Advisory: OpenShift Container Platform 4.15.13 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28180 — jose-go: improper handling of highly compressed data
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:16d1cd137a148d247b5b1a0952af1afb28ad6cad192c18220a75ee7c7a6a1576_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:49f41cc5cc87e1b62fea848b9cff9bd1aa4a5b65faa2102e56beed48a2e59684_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:616563dc033b6432870bbcc13f684750d3c3f84eedf813f2d704ac78ca41f5c0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/cloud-network-config-controller-rhel8@sha256:7904451d6c05c6b22efc292d389cc979a4123f5efa9e7762a4f5791f7e966e75_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:2e1670e354ef6c5e66bcbcd5cc4bc55d44d19cf3d766e0208000b405a00b8565_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:4a92ae75dea8d65298d2ab219b995ab39039d0b3e2cccd28e34a8392a51b3550_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:985b72435a7091702a520581eb51ebd439bfe6ff39c33ffaaad7e30b9e321454_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/driver-toolkit-rhel9@sha256:ebc879baa713138d4a8ad160f1e4e3157f3b3446aa73c15ca4ae273edf701010_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:164031c583eaf0bfe89062a96d4cd32fd3267ccecc4dedf262beaeda39e81882_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:5ce5f0996a18120d24c4dedfce7d8ec0f1dccbdf5048fd4a0174791560ab5a9c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:725393679331ebe39ef58e3ae1cb9b4da511666e2575c0856420e2a5901f324a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/egress-router-cni-rhel8@sha256:73df4eac7e1479c3d21196f21d58039692ba66c306b8c2e67b79de8a785f57be_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:196b9191bc5cb33edde239f6f6d2070e9166af5c00de546791c1fbc9aee855b5_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:1a092755ea78e3d74d3c26d9158ea2e991f71da4333c36f151527dfe9e2ce044_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:2427c8241208d07dec239295b60c24932f8f694b6ac66d737141e06f6c302c9a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kube-metrics-server-rhel8@sha256:cb1d90324c71dc532c26faee09f211cce9399ece9a3f80a74260b7741c838811_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:0354d105e3aac026bbb7d4b7e0a7da3002639d5f7d7007f8725f221694016382_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:5638a0b27bca881a2a79bae2afef391e2a1e44da090d13a75c0c79ffcf99a7c2_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:9b30ef6ea5d8e43ea6550304d2d6b6eb6dbf4befdb156f74c22ac4249d342e2b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubevirt-csi-driver-rhel8@sha256:a96bfd39939395fc5b13506c101a21e738e41f0e969e1694ce2a99d36ce824c3_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:5697b70e4e939dfd07d6b7b7c50e0f065d6d3c2bf898b38f14fc54562e24e90f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:700e807ae1791552f99db70736a35780590da07dbc42298fb227914a124bed5d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:9018fdcb1f190fbd1b06df0738abdf94cac834145b893e59b5f1c6c151095920_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/network-tools-rhel8@sha256:db20ebf37a9d5d913c92f280af049dea510b7ff9d807a44be70c1dacd31127e0_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:136485c9555f6c9d8c646558fecc270fa49236be75357fd75bfe748a44c8c861_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:6c7f2ace373ccf12bebc9ba4d882a350fb0be3ee6453920eb8c6010ef8f46823_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:d8c85a346fa84e12ecda6a2212d06fcd0394459ec0f5c1fd51faae97a545bddd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/oc-mirror-plugin-rhel9@sha256:e4c3a20a00f78de79ad452edd9c4dabd196ab55f87131b479e5fec9fbdc5060f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/openshift-route-controller-manager-rhel8@sha256:7cca648add5e643fc77f4a4756950653bf2d4bde20173a7446b47d8f8b00f775_s390x as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:e7e6e89eeaf682eb2f9987a900386e950e433fe909eff779c27216919c8d5f2e (For s390x architecture) The image digest is sha256:0b4b8c0eec3453f238db84c24020482399d945477ee6512ab330793830d6c705 (For ppc64le architecture) The image digest is sha256:63878604c612bcec7aeb077206ece7283c8d1970e19228d1e1fe7e9f989e236a (For aarch64 architecture) The image digest is sha256:af099fb0013ba4fcb975f5739d3083de8516d2af47393059bf8307be466d112b All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2024:2773
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224245
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://issues.redhat.com/browse/OCPBUGS-25858
- externalhttps://issues.redhat.com/browse/OCPBUGS-29929
- externalhttps://issues.redhat.com/browse/OCPBUGS-30152
- externalhttps://issues.redhat.com/browse/OCPBUGS-30413
- externalhttps://issues.redhat.com/browse/OCPBUGS-31747
- externalhttps://issues.redhat.com/browse/OCPBUGS-32506
- externalhttps://issues.redhat.com/browse/OCPBUGS-32515
- externalhttps://issues.redhat.com/browse/OCPBUGS-32716
- externalhttps://issues.redhat.com/browse/OCPBUGS-32953
- externalhttps://issues.redhat.com/browse/OCPBUGS-32977
- externalhttps://issues.redhat.com/browse/OCPBUGS-32978
- externalhttps://issues.redhat.com/browse/OCPBUGS-33038
- externalhttps://issues.redhat.com/browse/OCPBUGS-33133
- externalhttps://issues.redhat.com/browse/OCPBUGS-33208
- externalhttps://issues.redhat.com/browse/OCPBUGS-33224
- externalhttps://issues.redhat.com/browse/OCPBUGS-33271
- externalhttps://issues.redhat.com/browse/OCPBUGS-33277
- externalhttps://issues.redhat.com/browse/OCPBUGS-33291
- externalhttps://issues.redhat.com/browse/OCPBUGS-33305
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2773.json