RHSA-2024:7921MediumCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.17.1 security and extras update

Published
October 15, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp

🎯 Affected products192

  • Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:07f26e8df837530ffc4f2909e973b01c405bfa570a478d4c73415d2152a61600_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:0d5cd4870df13bba18e40b4b8a816ce1715ede5f2f76c3ea3362f51c8eebbf86_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:163316ca507138e61eee40dfae05cb70c819de18eecb31ae0ace4e4018e64772_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9-operator@sha256:8c5ffaea26a3c2a5f868980988aa79ebbb8fb8e551121994b8210f845c26d2bd_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9@sha256:0040cdfeee943201f8ea84dcb6c1d9819ba0ff25cf0711e1768b09a207080c73_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9@sha256:41c6e31f89fa6a2c0aa91b1bf43bd89097c6bcdc6201a0bbc34b295b69eb6621_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9@sha256:763f770243db8f424000ec26c53b1ad48a4e36f9b6a60c4cb87e3ac654e706d2_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ingress-node-firewall-rhel9@sha256:96b3521b7b8c1f56e7391dd007776b3fd4393d7a0d1e025abe7e10f80c7434fd_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-compare-artifacts-rhel9@sha256:0cd7bfda5e642ea6dd4575edbd2625d0f1ad41a9d9648fbd5647b16be8b5616d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-compare-artifacts-rhel9@sha256:0ec5fc9c9e44bdf73bc064edcd3369eedfe21c1f9db0bb9dbb6b2ba53fb74719_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-compare-artifacts-rhel9@sha256:95f6056630d84551429b061b70514231ed9c1ce9205ed85dda47896cbd4c2331_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kube-compare-artifacts-rhel9@sha256:c5cd07ad8cfa4ab16f314ce519a90d1f44784a083fd39b6eadd8896ec8afc3b9_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:0612aaaaede1b73f16e09064dc654d9950f522ff4396239a8757957c8ea3f302_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:9310bcc462968ef7d67248cfbe4b8cf98ccb9cccedc19a8ef7c10f4dc17f4bc2_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:b941349529c0f2e587981b32bf59e210a999ac676f66bf6bfd97ad58fc8e4c3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/kubernetes-nmstate-rhel9-operator@sha256:c1f654fe5e47c256cec18b95a50d87f9128ed6d3f84699e310aed0288793ece3_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9-operator@sha256:34a3529c797edbb7ae12abe4e76fa1f7a40b4119e54f13bc2e7298711a91731d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9-operator@sha256:4c3ab3e6976504d7d77cda951e7acbd1b856a6c6108e0252bf47fbdeb968f50c_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9-operator@sha256:c0d0b09b8a17b3a5274f3a48a43fc4cffa498e48c51011391808aecf3a9cb20a_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9-operator@sha256:d17f455cac4386efe07d0f1780b668b7928dff2945778cab5eb3eaa7f53bed6d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9@sha256:19a17e229712d1f50b785a3aef8f325f574feba4b2746db6a7e602523bd5509b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9@sha256:661226ba50657f52f1a2770d8944604847bbd65abb42c429276211e50fbb4766_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9@sha256:c4ac3471264d0be458c8476146917de2fd18a5e12aba38cdeb1033f7a062161f_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/metallb-rhel9@sha256:da2b79f7447f7c3c252985289a008afcbc4c04a97aaeee11f6e7fddee8568667_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/nmstate-console-plugin-rhel9@sha256:31835f3842c3de0e95f8fcf5987f93cf87e7a80d0a2d316dad84b510f2f0ff3e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/nmstate-console-plugin-rhel9@sha256:4dbd250648ec5fbd6cedd2f4db6163c87a4ff75e1ebaa57805f40e92224edcaa_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/nmstate-console-plugin-rhel9@sha256:b1a7e033b1683ad38030081d707b123c0247401eb7e19aaef34ac72787c6bf15_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/nmstate-console-plugin-rhel9@sha256:b317ebe9195a1ca8acd22978aed512c39d9f95244000630a60ea22fbc7f999e7_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • openshift4/ose-ansible-rhel9-operator@sha256:39e5a17bcd573f8186ff2a2f3d8adf86bbc7af30827082f02e2e139a25ce7e58_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • +162 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html Workaround: As a workaround to stop being affected otelhttp.WithFilter() can be used. For convenience and safe usage of this library, it should by default mark with the label unknown non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it. The other possibility is to disable HTTP metrics instrumentation by passing otelhttp.WithMeterProvider option with noop.NewMeterProvider.

🔗 References (5)