RHSA-2023:5006HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.14.0 bug fix and security update

Published
October 31, 2023
Last Modified
May 30, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2018-17419 — dns: Denial of Service (DoS) CVE-2021-4294 — osin: manipulation of the argument secret leads to observable timing discrepancy CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-36157 — cortex: Grafana Cortex directory traversal CVE-2022-3064 — go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents CVE-2022-23525 — helm: Denial of service through through repository index file CVE-2022-23526 — helm: Denial of service through schema file CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-0475 — go-getter: go-getter vulnerable to denial of service via malicious compressed archive CVE-2023-0620 — vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File CVE-2023-0665 — hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-5408 — OpenShift: modification of node role labels CVE-2023-25000 — hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations CVE-2023-25165 — helm: getHostByName Function Information Disclosure CVE-2023-25173 — containerd: Supplementary groups are not set up properly CVE-2023-26115 — word-wrap: ReDoS CVE-2023-26136 — tough-cookie: prototype pollution in cookie memstore CVE-2023-27561 — runc: volume mount race condition (regression of CVE-2019-19921) CVE-2023-29401 — golang-github-gin-gonic-gin: Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🔗 References (1325)