RHSA-2023:4986MediumCVSS 9.8

Red Hat Security Advisory: Red Hat OpenShift Distributed Tracing 2.9.0 security update

Published
September 6, 2023
Last Modified
August 13, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24536 — golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption CVE-2023-24537 — golang: go/parser: Infinite loop in parsing CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters

🎯 Affected products55

  • Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-agent-rhel8@sha256:245b3a4fcc6ed62f74679e620284095a7faae32b796571dfd55f1a9f2f05d683_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-agent-rhel8@sha256:d26cffb00efb86685fef638702f583f7c157f157246c87366a8d1f77b777cf31_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-agent-rhel8@sha256:d8bc6495463d50293f954ce8dd7f70e0416e78baed86cbd4355693f701593c17_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-all-in-one-rhel8@sha256:26e1ee47bd0d2ca13b14dba616d333d3c0164e7758c893bc6813dfc49bb29040_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-all-in-one-rhel8@sha256:6fa1ece1d0e77e540fb80648f318810051025646962da4752420edf6da43caa5_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-all-in-one-rhel8@sha256:8af8b45b6a81bc08043171c76414d3e07f96ef160e9d46867ecc7d9b904465eb_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-collector-rhel8@sha256:3c69ca16cc58b5472a20aa7feb7f290f97b73125b0f9c9982c87ad4486e8414e_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-collector-rhel8@sha256:595b6828dd9cd8d1b6643682ada8d1192cbb5c65a1cfb9da452ad184d2523223_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-collector-rhel8@sha256:f48d37bf230ff3b408302004e7e15d6cd0dedab5877d867b3770863a9d38bea6_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:510f2f64e5e24c527541300ac9349a8e0ebc1a4856fc347aad5f5f5b187d2225_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:acb3481b4a9640fdcea057098d8bafdc17c80dfea8beff51aae912d31d03fd0d_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-es-index-cleaner-rhel8@sha256:f1753cf36d7a657a4d60107b342781155289119b39976ddc776c8dd976051766_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-es-rollover-rhel8@sha256:05c490e65a007d04d9006e9be375dc3015eec3ca0c538d5ff24a1b5129c23752_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-es-rollover-rhel8@sha256:97b4b06104ef210e6684f00d2b58406975d08342b8ae537dd3b54c87223d5752_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-es-rollover-rhel8@sha256:f35f3b371550adba3276ec9e969b51d26b67380294f3775031cda4b1572be084_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-ingester-rhel8@sha256:0e0439a327c78aab214d0f00484fe4dafb1c214dfa63c9d1d520f0becc05ae4f_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-ingester-rhel8@sha256:476cece9d0a3a846c4dc008e13ebe86cf52fb49b0963224c8d83ffa00f99baa1_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-ingester-rhel8@sha256:f4fb59d36ac33e3a5c5b5eedcccfbb039f4ca50e61cc7e1bcb68ed89b0903745_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-operator-bundle@sha256:cd4e0e2caa098465cbc2bd770904f471a9a95059145c01bd4c17689c2217bbd7_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-operator-bundle@sha256:d220c38ea995ebb78d9df0a8a11c56fcfcc5f26cd6e769cf90c6a703914dcc76_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-operator-bundle@sha256:d60fd47d90d3195ade9ff821520337dadf4128061a3cbeea2eb7bc28f4647e0a_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-query-rhel8@sha256:1934e02db3e8462475b7ba51860fb7df81da92e5c3cbaabc2eac0a88350d176a_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-query-rhel8@sha256:22177a3d088095292aaae48023477e3069f10cf91586f0236e02b481098eff2d_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-query-rhel8@sha256:e5d016116f2d35dabf0e445a920966581b15292bdef782d126f5a56c60077055_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-rhel8-operator@sha256:da1cc99bce2cca6127a887fc4c2190f97fb7b5ec3be119cc8ff6bfb2cbc4606d_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-rhel8-operator@sha256:e04ca83905b906b2ac22fab5420629a61f9210a3a4779a60966813aaced99541_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/jaeger-rhel8-operator@sha256:e81105452ece3ccd9d1e7cf9f91d2fbbb06f12b4892289ddc94b0e922321589f_s390x as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/opentelemetry-collector-rhel8@sha256:0604dab5223b184fe502a493e7d2e96082e17ef3cf9864f37d889ac18aa19876_amd64 as a component of Red Hat OpenShift distributed tracing 2.9
  • rhosdt/opentelemetry-collector-rhel8@sha256:5cdc56e19e233f07820de14aed266ca8d9121fc06bedd6189401d2f420206901_ppc64le as a component of Red Hat OpenShift distributed tracing 2.9
  • +25 more not shown

✅ Remediation

To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, upgrade Go to version 1.19.8, 1.20.3, or later, where the vulnerability has been addressed. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (19)