Red Hat Security Advisory: security update Logging for Red Hat OpenShift - 5.9.6
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-0286 — openssl: X.400 address type confusion in X.509 GeneralName
🎯 Affected products43
- RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-operator-bundle@sha256:e04ce5eaf023bd299b40c3c7666087404e41f6cc9a2342247024d8ac89bb87b0_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:250181cdcdd3167a25ca351423ad7f727ae88fc6a7b0a539f58267a8f1d8967b_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:4caec5ee0469d1a8f2faedfad20acd93aa5119da5920552852af6b9cca31286a_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:50f07777580d38ca952df7afbfbdba16dbe56cf1bd39eac0223cc09a97f684e7_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/cluster-logging-rhel9-operator@sha256:e6922b8a8ffc13776fa979350b3b405cc54bf58291ffd2147587e9ea0db8103a_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:4586853d6350b0ca6003929aca8826fc4596cd13a33ad803a5f10363a1fc5d4d_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:477ad04024ff5d04e8c2e1e1fa0965d5bf2de1d6ae81e41574102060543bf105_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:8f1349a66aafec3f7d58555ee62d8d41211feacb2cf142dcfa8183521b2fdbfb_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/eventrouter-rhel9@sha256:cb07ad8e299a32a432eb64dba905c28f588175eb7552b3cac4797887f2e3126f_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:00d1fd2e056b38d1ba768c088883f39f0a7852ccdfa6a91744ea2ba9e9ab840a_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:25422425899a2fa5cdc83a4aa31072d717a42483b5a7df9c485e13b5fcf19207_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:dd82c39b7456db7c3b82fb80173d831a9502305b45ff2c49b8ad3790d59e27c1_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/fluentd-rhel9@sha256:fa96f841fc8ae3a604ddabfc37f809f3e6a347f72a5064dd76ed8b040505da44_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:2507ce314e9d9d605e4738d1a6e86a94eac7c79dfe804e3fd6aac65bfe58bdf2_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:3a04a0c94d59ac70e6f3bba7e841f24beb4e7ece4fc006140a6460141461da99_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:4e004498e446d80475601c1260a16f879f455a38deb8c89f19c2cc1b9ca6834d_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/log-file-metric-exporter-rhel9@sha256:5a48b412f96069c258bdfacf7a2f7fbcec1ec08c8b1d9c6a8d36b419e440dc76_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:6dfc15394c7f8de99fb777a9cac7019afaa4ab90cef7b6a9d76c2612ade28cdd_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:cc27123d734d0aa1a661595b3f79684c7c523332cdbe531d3421210448733c3f_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:e6f2435803484f9f3a3ed1c677dbfcba0dcc1868d95d46dfea61c09b79dc0acc_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-loki-rhel9@sha256:fc26a8ba1fa06feb4da0f55be2b55d1c29762c5e5255a93a6081ba993f84c077_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:011220d3f86ff9ca782c97ac75d4848e794fdeebb64cf8831548bc072ac106a2_arm64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:a319832e0aeb74e6f43f695b9956fcb1f8422adab20974a242b9be415bc2ad4c_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:dd9abb806b3d8bcc636b8fb8720a926dc43e208c5c5d447f226cd2094689a8ac_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/logging-view-plugin-rhel9@sha256:ff52c6ce681a4c9a9824b098d2da9cbccdf4cd99aa9c25c8cf62baaf2dea7c4b_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-operator-bundle@sha256:76ddb9f56971649a52d0b66fa8a2df3859f7a4e9f965ee64cf1bd81a94b72d56_amd64 as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-rhel9-operator@sha256:03fa793ec87087a9c186ec4a6bdbe1ac598a7823fcae97b420c06341a38a1caa_s390x as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-rhel9-operator@sha256:67d91441202f52784c16f034d884a929e8bae648c27a607dd771f56c778f3951_ppc64le as a component of RHOL 5.9 for RHEL 9
- openshift-logging/loki-rhel9-operator@sha256:72ab9feb4222b622f5ddc4d16b89ff2d30fd6fc05f2bf300a80ad46e94749457_amd64 as a component of RHOL 5.9 for RHEL 9
- +13 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html For Red Hat OpenShift Logging 5.9, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.14/logging/cluster-logging-upgrading.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2024:6095
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://issues.redhat.com/browse/LOG-5525
- externalhttps://issues.redhat.com/browse/LOG-5585
- externalhttps://issues.redhat.com/browse/LOG-5602
- externalhttps://issues.redhat.com/browse/LOG-5815
- externalhttps://issues.redhat.com/browse/LOG-5866
- externalhttps://issues.redhat.com/browse/LOG-5988
- externalhttps://issues.redhat.com/browse/LOG-5997
- externalhttps://issues.redhat.com/browse/LOG-6016
- externalhttps://issues.redhat.com/browse/LOG-6023
- externalhttps://issues.redhat.com/browse/LOG-6028
- externalhttps://issues.redhat.com/browse/LOG-6033
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6095.json