RHSA-2024:4468MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.16.3 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors.
🎯 Affected products179
- Red Hat OpenShift Container Platform 4.16
- openshift4/frr-rhel9@sha256:111c391f64c85d5c27efefc263b8986c7cba375453917c4b417752cf75e19500_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/frr-rhel9@sha256:3f9179b61cdd57bc85911d3e23f5a0248572f56278ba106f06e802c8175ff55c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/frr-rhel9@sha256:471ab63b1c92d4e297018ffb8203f193346a688631be94e8876050058cbc3830_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/frr-rhel9@sha256:89b9a3047e6a8f81fbe7f50bed09ea0dff1db52c4df68c5b119515702889c8b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9-operator@sha256:0ce4e1d510f417be3e709d3059014cc8d245778e41aadb8e4c37d35e3cb85138_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9-operator@sha256:18008e314efe75f9cf14d45671a20d2910413255523949161bb83b0ec77355f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9-operator@sha256:867dcb4c652f1fc579c10d3cca0d9f1a345ebc803d7df0d0c227607358099fca_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9-operator@sha256:cb9a2f0dda872ad806d801e2e3b3fc3e8aaa73ce1cbb7b39bf994b02d64d3236_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9@sha256:665f6bfc94a1d873f377bea5ccd25292ff0bd6ec0f5287fd3e14f4574dcc950c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9@sha256:bd430bee1f4353d81d8f6e0dab52f083bc265525dfb3cae0da87dc05e8dee990_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9@sha256:c2ddc6ae7c52e9113d56ad31da8c6e9158bc041b25333c156d71d50e594d82b0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ingress-node-firewall-rhel9@sha256:e7165c3f3ab3742bb0697d9348b8cfa71d2bfd3b08b6eec133bfef5171088176_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:4f86cc7d53683bb20a4bb2113d21d1952423d178343c95165e62f339291d251d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:561282e63523afaa3a7848fd7b06bfbd8fa6d7a52109b1502bb70c13fc8df9f1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:6829be78bb88afc19f90398ae974e36fc88a28e147a2ca34ffa73e25e9e5f7d7_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:de96f11c3ef9eda6ae709b1df9fed25a7e2bccc559eaf3e57db7cfc4e87d8523_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9-operator@sha256:6c14e5722caa1cdfac116f91f4669d720b38120796d7590d458fbe317cee7170_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9-operator@sha256:a600a8c122a157e259120d0ed83bff4a647fb09da12f6ed45a874b11a7959fcd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9-operator@sha256:c3b3eef83715e8b3e06a382070455155c0454b36c7a92f5033bc9979a513c24e_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9-operator@sha256:db1b8f768dece369ebf04fca2839913050d104e0f447901b345836e456812d3d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9@sha256:53f75a784b18c490e5c4dde5c1d7b7aa98eac1123debab99cb874f5e43fb0c2d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9@sha256:9339f77c60c1f166e0648a16cd94c9bada3e2515e26e3207bac50b896a64ae3c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9@sha256:9acf4081ce13ab59eb6dbed7e76e845fefcbc5e9b4ae0119a35d3868aace75e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/metallb-rhel9@sha256:fb0581fbcf4c2ed5f18f679974ef5d739c8672f798876b597d5f99d5f90a4f7f_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/nmstate-console-plugin-rhel9@sha256:03f66b2be94d96ab2dfae830d12033ac7a2de5115842d3d91456402c832628ae_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/nmstate-console-plugin-rhel9@sha256:1f416b5abae46daac1a1100d50b2fa05e2f300e0c2a4998fc6e6222d6431abf6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/nmstate-console-plugin-rhel9@sha256:70f362a1107eb4940d222739f69506e5b764e4b822eb7b92ebfe0d794bd288d3_s390x as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/nmstate-console-plugin-rhel9@sha256:7db5a2e1f5b2a4b63d18b907af835b2997b34a45c23e30b5fb3cba14c946954a_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:bbe40b0f1f4b502b97b72ee31891be8e5bf364e23b0dc97dd6f86b31840569ec_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +149 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:4468
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://issues.redhat.com/browse/OCPBUGS-36307
- externalhttps://issues.redhat.com/browse/OCPBUGS-36308
- externalhttps://issues.redhat.com/browse/OCPBUGS-36507
- externalhttps://issues.redhat.com/browse/OCPBUGS-36509
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4468.json