Red Hat Security Advisory: OpenShift Virtualization 4.15.2 Images security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-26159 — follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-45857 — axios: exposure of confidential data stored in cookies
🎯 Affected products101
- CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-controller-rhel9@sha256:05c354f5775ffe9eb40a70723af9710589315126049c2b0613729a7601fea711_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-controller-rhel9@sha256:3b5dd9a5217af5db0347efafb380e91da1a1176e2b40f356115e870612b79928_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-operator-rhel9@sha256:15079d40fa0e418fec82620b3f52e394743c9d7f0433f2b8aac3484fbb57b790_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-operator-rhel9@sha256:2519a913edf163445c0819c465f3323b9d82e10bfd34129b79f83f5e395a41b9_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-server-rhel9@sha256:146b827825bb5222ad360f8672d4ef34989518b43369b641fc703eb704c891a6_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/aaq-server-rhel9@sha256:96de7d4fd401026664eaff799585823a5906b7e72ed24c685648086f1e1c02e4_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:09b473b05aa69cbc131c52ceea7885dd6a7367ccb80f6d3832da9df4e61cee1c_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/bridge-marker-rhel9@sha256:35ac9c93a2b6571ca28ca1e13e040d7a06113ec9a768c02e8c0735f76c6c0b69_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:690a5b5450c77fbc2c9928ff7849c447a6ec015f4dcd481060c49250a5509358_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:bf42cd420929b12d78ebd7567b4de1c32ea343f0201ae7ecfb9d3a47b12220c1_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:389e56fa3345ea9866b9c7789ff9ad04d3ff2b45db91eb13b20287960c6fe72a_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:abf9f568d866433b9c1a4f08b63ca6f11543171882694179b37b70feb75257de_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:207cf6cbaf6a79f15146c8d6dba36979303e07f9793ace901b97e330f167ecc2_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/cnv-must-gather-rhel9@sha256:cadf6787d391f64df11112c29d7c8f2b3f9eb312e478d8cdd8e634401d390834_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:26324b49a3da9d17d5f3814b54cdcfc839dbca423800aeba48774a774d79035b_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hco-bundle-registry-rhel9@sha256:d9f6a92e9f8e1a14b243dd1c28ea3e2c3ad7a45aca410b8f4c24e697a32a57c4_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:5c91f322e434d71a762cf13bbf0bbd94dfd12218a1bc263b688388bc1ad57ff1_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-csi-driver-rhel9@sha256:5f5f0b425c59626724f5e09ded54c670ac80b2c7279d49f61d9e40306b07e272_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:0199a42c1b7a987ec91a4e33e7fdbdcc3ac6ce6dd5a1ece9edb03ac067a1b696_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:bd4e4565518629c98f5bfa87e459425f9efcc8312f24e9428556d8593cc91f16_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:366ce321638295540c24a2ad7e05002c2ab23ef793010acd9e248729baf9efd8_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hostpath-provisioner-rhel9@sha256:cb5d049a9c06d01ccb8548d6111e051263dfdfd99cbd8ecf1215fa0de692e8bf_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:417c74820c9996c9ed5958be73b4e2edfb62d49d8afdcac819f70c9b407df20c_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:bd5a3c794887ee63ac600a0d0298092196a2e642a92cc33bc2cfb3f751811dfc_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:0889491602786dc9ba90e09b2744448be3e36e60a1525020566855bdf950d460_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:66fa300a526204e9f4925b5a7d554bcce225935385625e040cee6fe75a44578d_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:17727cf133d3fbf9865bf7f9ae1a09a40fd0d21114a38a046ecffeac26ec2e61_arm64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/kubemacpool-rhel9@sha256:d1296ec61183139682510dde727114e406c6072ae8d4429b983f878c1bad8b21_amd64 as a component of CNV 4.15 for RHEL 9
- container-native-virtualization/kubesecondarydns-rhel9@sha256:965e1b1afc72a7c96d2f90c673ba07f3856cc646017e222e9d03a9400f72cf1b_arm64 as a component of CNV 4.15 for RHEL 9
- +71 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk.
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2024:3314
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248979
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://issues.redhat.com/browse/CNV-34292
- externalhttps://issues.redhat.com/browse/CNV-34963
- externalhttps://issues.redhat.com/browse/CNV-37007
- externalhttps://issues.redhat.com/browse/CNV-37018
- externalhttps://issues.redhat.com/browse/CNV-38360
- externalhttps://issues.redhat.com/browse/CNV-38599
- externalhttps://issues.redhat.com/browse/CNV-38661
- externalhttps://issues.redhat.com/browse/CNV-38699
- externalhttps://issues.redhat.com/browse/CNV-38845
- externalhttps://issues.redhat.com/browse/CNV-39100
- externalhttps://issues.redhat.com/browse/CNV-39557
- externalhttps://issues.redhat.com/browse/CNV-39686
- externalhttps://issues.redhat.com/browse/CNV-39704
- externalhttps://issues.redhat.com/browse/CNV-40159
- externalhttps://issues.redhat.com/browse/CNV-40904
- externalhttps://issues.redhat.com/browse/CNV-41508
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3314.json