RHSA-2024:6755HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.16.2 security and bug fix update

Published
September 18, 2024
Last Modified
August 24, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-24789 — golang: archive/zip: Incorrect handling of certain ZIP files CVE-2024-28176 — jose: resource exhaustion CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak CVE-2024-37890 — nodejs-ws: denial of service when handling a request with many HTTP headers CVE-2024-41818 — fast-xml-parser: ReDOS at currency parsing in currency.js

🎯 Affected products99

  • RHODF 4.16 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:1855a0b57e087edfd1d1c1345de2422f5cbb57d8cd684bcc467676967988b93c_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:5c030da386a9b03e6840a6ab029c02570c95ba06845601724fa167c07e9eb8d7_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/cephcsi-rhel9@sha256:80d2812e1d0552f98cdb5095229cb904ea38c9b7523433ec14a04309fee65bbe_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:10b1d93f122367a248bcaec7f6207679ee037f1898af43f87c4cd20a52977892_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:2a6eb645330b2dc345361bfd58cfec277865f9020388c2b0b16822660a6c3239_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:9525321c9555ceb005a6d38c7b40b429875454d5770da138cf5aa6b1c9b36d74_arm64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-core-rhel9@sha256:f4c4681f7cfacae5dbbe4bb54b095813a8991a9fbf681c17794834064065a526_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:d7c2bc78aace609338662cccae23ac48e591464232ebd0b7bb540417281c6569_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:ff2fb273110b075237abbc1d4f3733e4d40b8c8c9732d1297321c30cb1e2b4fa_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-operator-bundle@sha256:ff42a4a6faa413d5313a375131a9da1af2aab2d6197f1a3317f733811c37f0dc_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:2b62fe6cf2ee2f076d5917216509f0edda8dea1b34dae19bbaffb93a30ac8c32_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:2dc4a48faceb2ccc1f3b33a996044e2a7c5c8d2faae6c229fa3a750135665fdc_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:4960d9c4d370a301cbd44ca1747018678b1141bf44d5eec390f7dece2cef8c07_arm64 as a component of RHODF 4.16 for RHEL 9
  • odf4/mcg-rhel9-operator@sha256:b09fcf50c81e27fca918134a4157838645c554a809cb8eb44593770d09c40288_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:5cb62277759ce0b63ee6c37a5c5379d72fe50548a616de86f2b198f068362b73_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:8fa8fc3ed821448c787c9ef2a79f0388a0038c11e0f054b7dc57c49fe5fea5e6_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-console-rhel9@sha256:e4b92ae33787a1a666b86f0657e756b35665b0761a6ada7046a01ec7a4fc2387_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:000ca7e39c0b730f00049615555e41e5eb7592dc673f5a866459ed9214a8b6fb_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:8543a33eec1139b26304b51e6a8be642af65582305d17e0942c67fc1df716351_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-operator-bundle@sha256:8c29a95e5ad2931245c6a69848b6060fe1921061144ecdc184840aaba5e32309_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:19e503d397bd79d0322789b023ce7fdd6f5c8e3ce077a7b2e290f88fbb084b59_arm64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:44168a481eb3f08339918d34fe651f9de4b77a68de493513a2392532ad847304_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:c4529335349d7c4f71fce929a49ed3a850cfb62029e271f5cc6a3357fa9026a1_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-client-rhel9-operator@sha256:d0335bdb39ba92e2dfd5012c01c4e0716af473190612cf456e6b2b36c5b805f9_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:0f8c7c96f43c7cc3af66cf632ee85ec12591d0ff5509cf7d97daefb45fa00cc4_amd64 as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:ad227c3ed05ed0783b5633e69f2791c12bc53a72f1af79c55a714d48222ca852_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-metrics-exporter-rhel9@sha256:e71b2b760cc0090920f2881eae49ac78ca9c374e493fa1a4095985e3a27d4187_s390x as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:335daf33b13e5b116d6f15f106d50705a179dd15820da1a0dd88d8ba02cf07d7_ppc64le as a component of RHODF 4.16 for RHEL 9
  • odf4/ocs-operator-bundle@sha256:9a3fcbda671d1651c2a1829d878c29d7de526217f903719e766fec7bf8330e1a_s390x as a component of RHODF 4.16 for RHEL 9
  • +69 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The default stream concurrency limit in golang is 250 streams (requests) per HTTP/2 connection. This value may be adjusted in the golang.org/x/net/http2 package using the Server.MaxConcurrentStreams setting and the ConfigureServer function which are available in golang.org/x/net/http2. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: The issue can be mitigated by reducing the maximum allowed length of the request headers using the --max-http-header-size=size or the maxHeaderSize options so that no more headers than the server.maxHeadersCount limit can be sent. The issue can be mitigated also by seting server.maxHeadersCount to 0.

🔗 References (29)