Red Hat Security Advisory: OpenShift Container Platform 4.13.42 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-1135 — python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-31463 — ironic-image: Unauthenticated local access to Ironic API
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:816f43f63c7e2c282223a23a7e1770fdd2ac1aad4ef1a9e92a46917dff7fad6d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:acfb52e6776e2cce0b0802db511691a07a8324183e724b388ea03c7f39aed404_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:d0f8871450dad4975d85f0f6709d56f7e20f3cf9c07c6c6a7585f4d80b235d2f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:f9e278ded9b87183b6d66e19ebb111e4cd52a43277800957ba1b144051b48f5e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:1536fd0f2055b1b007a76653928043714c954c2bfd66f12a52438411c6e63cf1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:24608d3565fed294d01ad308a3c57d064e3c29b05d771092b73466c3fc580396_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:584e35657c29d6a9fadbe3ada5e44299786423fc4eee9758306f08f3b78409a9_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:fac976c88f806e2a266f72119a0a5df47846299ebaf5b43097e75af4e4e9608b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:3f48d6763965fd2bf0a7348951fd109bd37800a67b70cd7670811fc226cd9d73_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:93b19dd57c3e819df4155a38dc6e2d4aa8898e62632736721cc4b51a51178965_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:b44ad6d7c5b93a307ebc805c0966b546c174059098fcfcc3529d5ebe59132f98_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:c1cf5b33663741cf9974189763ac75d81f7453c4898c258baea6b62b604317b0_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:1eb36858b2985d547214e795ea20be5e40d0bc94b6b00db991200ee234aeecf3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:af3ec375d70250e8fe392b5d0b9ecf53088a4ba93ae26829da46ea2576156c11_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:c8e0b1c62fc7eff3abe325a53d1bf40dcb0db5c4b15825064efeaf301f271d7a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:dfae04b6558ea3c914704817ee8d38c3609ff74cbe26e8abc07e5b8e7986a78b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:107156f36b72a5a21dee7aa7367352e97c4e45981f727e2c80311725c8a4c40d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:9bcc07ecbf8f28d18fc814837d4ae86c80a5328e9a2c593f94edefec5aff79aa_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:a6332e27350a65ae3d31298210dcd413977c0e82b6c10dd2740850f490c313fc_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:f12677aea04815177c46726d376d660cc5fd21704f1f8e215ae9d32f03e76e1b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:5d3b3b7bfe52366aea8db42f3ed0a9ed5958fa632f404f3be8f718e8aaa4c878_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:24fa5f35e52b8e05f04afa1843b5390c9921f2af2d9e08d795cb9b9a7e94ebb5_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:40e008301b66ae6e3b83ebc30c9176d904f7487db1009534d81ccc4ebb693308_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:b113634c783bee75a7f792e80a14d60d7b7fcdea7eada9d1e16d7ad589a7e2d3_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:e2e18b38d580e178c712747c8b481f837c71823941fde080fdb57da2614e8a14_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4b86a3a2a82f736b7e2c55a5340aab344ff9a067fa2d146b0ad10fb706b92f2d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:9b26a14030b1e76f5c534b9b99d0317bb2902a34ec49498068b926e2831ae994_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a07c9da87ec0ae12e0f25944efa57d2b3fdc216c7392488e4e0aa3784694b37f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:aa49fdbe6b16374e867f2b08f6e312197a219ebc7c04a6df835963c7af1b8692_s390x as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:dcf5c3ad7384f8bee3c275da8f886b0bc9aea7611d166d695d0cf0fff40a0b55 (For s390x architecture) The image digest is sha256:fbe90883f2a74685b91cfe94521084a1d18682e0f9d06bd509693557d31e4772 (For ppc64le architecture) The image digest is sha256:6e6efacfb8366ee4cc0adcaac0e1cf6b041f2d343438732f1a76d19158435cde (For aarch64 architecture) The image digest is sha256:68a3d7b07722692b591d33e4e8377339c519ea875113dd1ced489dd67e199eaf All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Below are two mitigations for this vulnerability: 1. Switch to using unix sockets for traffic between HTTPD and Ironic/Inspector (recommended). Set the variables IRONIC_PRIVATE_PORT and IRONIC_INSPECTOR_PRIVATE_PORT to the value unix. OR 2. Temporarily stop using the reverse proxy mode (set IRONIC_REVERSE_PROXY_SETUP and INSPECTOR_REVERSE_PROXY_SETUP to false).
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2024:2875
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275280
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275847
- externalhttps://issues.redhat.com/browse/OCPBUGS-18674
- externalhttps://issues.redhat.com/browse/OCPBUGS-32180
- externalhttps://issues.redhat.com/browse/OCPBUGS-33062
- externalhttps://issues.redhat.com/browse/OCPBUGS-33174
- externalhttps://issues.redhat.com/browse/OCPBUGS-33252
- externalhttps://issues.redhat.com/browse/OCPBUGS-33273
- externalhttps://issues.redhat.com/browse/OCPBUGS-33280
- externalhttps://issues.redhat.com/browse/OCPBUGS-33327
- externalhttps://issues.redhat.com/browse/OCPBUGS-33448
- externalhttps://issues.redhat.com/browse/OCPBUGS-33449
- externalhttps://issues.redhat.com/browse/OCPBUGS-33581
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2875.json