RHSA-2024:2933HighCVSS 7.5
Red Hat Security Advisory: logging for Red Hat OpenShift security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
🎯 Affected products43
- RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-operator-bundle@sha256:a75b8dc9936e65b2ffbcca73a47456b38e6a2dc406f39577c6646ce8d33c5238_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:16ab3024f9162cdb35e94994ddf180c6dc3ddf00a7a8dbeef439f4bd913586d7_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:387887a51d53040ab5740e4879802f1d22d517832a6ced9d23c816b8b99628dc_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:988d3b3d190f02843552bc389d25c5909b62547c2ebd2ca0b6f2cb82470dbd23_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:b681e152d1534c53b3c0eec088060dc2af74d5be33136ae7c2e19cad3d88d829_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:3b1c2089a6e83b1ae4ba64c42e882439054118f356fdd64ec916176a997ac854_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:9ce41fbe39e9483f854bcbffee9799f219aea90796062b2bd11be3440a9de525_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:a57906b3fefd8eb0fa0603cb8755278978f34d925720b8ac30098604cf0a4179_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:efb30e1aab21a9d2b68317c46e9c257c1342a0336296d9cf2702eef2300501d2_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:0c49b5b637eb960dfefbd22855f2a29690564d93b8afe52f0a437a85be919a61_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:47bff7b6c79af4793cd04cbec1f0a28ec2eef0d0f11dfe86aea87fafc369be64_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:6e0d349969484482a2e02e5bd65b0a2a14379118935cfab29d9b875aa1fc3b28_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:aaf2dd9162077621883a3b52bd87fe3a6a86275f3fc45dafe494ab1f97b62f5a_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:879b38f0cf7fa776f298a4cee08e35f92f35f792c42fbfd2f7a03f3f50bfbef1_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:d318895fe58db2b899d76975a18bd3858d4e76a6a5de5d2917ccdf3290734d9c_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:d80ef1784f96465d305c50888176db38b2566e9991769b25445d485d47ada5b4_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:de02ae0bf1936e581f2c094188885a6678487e291874f601a403b57a06cddb2f_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:1d40fa988963f381718d124e59387dad32d1d958e52f63a28ac48409bdfd1eec_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:249cf561231b5a793354263fd859382229a2c700639367ba8e12979385431349_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:d7a273e837f49536edc95f79fff0cefad5419717518390433200e7cbbe299194_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:dbfa3914b34fd20a494da31e1920e926417627656f9b2761832ddbdcdd3e780e_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:04e3d5de1f21d91e7234a0d2af6e096d02b845dfc1826cdeebc642eeda67049c_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:713be73184bd943c98edd0761eae838c73ef3e2ad3c54d5236c70fe4ed62e073_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:b1be984196fa8641d129c0a70e46651448b58516220a488efcb51f8639357f7a_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:ec1c839b591a2c7b044abf21486dfc998b4434ff2c23a93cbf393b714f6dbc95_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-operator-bundle@sha256:68dd8394cf3f44d9827cb7b8976044e23d92349262334c8def4b2d15cde7a8e3_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-rhel9-operator@sha256:06b890fc00bc1cd8cd0fb3264a0588ebc3bf8c581b1923aaa7fc56161a931b50_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-rhel9-operator@sha256:095068a422f174e35e3dfa16dc424c13e6dba5c59d2469a18fc08a1cf450e9e4_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-rhel9-operator@sha256:1ffc4bdc3b1ed8296208d63545e7a97a657c0124f7c27c616f2b56424f392025_ppc64le as a component of RHOL 5.9 for RHEL 9
- +13 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.14/logging/cluster-logging-upgrading.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:2933
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://issues.redhat.com/browse/LOG-4910
- externalhttps://issues.redhat.com/browse/LOG-5156
- externalhttps://issues.redhat.com/browse/LOG-5308
- externalhttps://issues.redhat.com/browse/LOG-5426
- externalhttps://issues.redhat.com/browse/LOG-5466
- externalhttps://issues.redhat.com/browse/LOG-5504
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2933.json