RHSA-2024:2865HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.15.14 bug fix and security update

Published
May 21, 2024
Last Modified
September 17, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2024-25620 — helm: Dependency management path traversal CVE-2024-26147 — helm: Missing YAML Content Leads To Panic CVE-2024-28180 — jose-go: improper handling of highly compressed data

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:34f5392d310e88f548bf4f840b06ea6c494767b2951842363f34c01150ee2c16_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:7708f3555792576a0acd6706274acb0e24ee7ba118b889ea6698068abead781c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:8d8a86ea24496b95fe4ec954fbc672c2d6b15b98b5f6f1e0a313ec96340e1cfc_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:bc8b31481f570d98b1a3f3e33fab2308adcb27f91004180347774c976aacb392_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:018011d9929006be70ad330fee97002bdc4aafd6e9f15a9140322b7668856d0b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:0732e3cfbb99bc9f0394110d1a2f14a956ae976e05a51e2de62f62abe2cdb1cc_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:b63254f7173f416a7cd94afbfb0837e62af05fba607a740bd45e9ae39fda695c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/egress-router-cni-rhel8@sha256:fa67ab59c94f2f4554514b1c40e7ccd68be7d8d42e2c557f49e9fc0f10fe7666_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:18c55a1ba5fdf5ba4ffd6faa483a37b1746bcf144cb75c90101a256e903c6465_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:1ee2b5c6dd46172f3a22f4ea74990f71efc7c7ac0a2bad4dc4682e00a55dd7d6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:8a975d84306c6045f658f04f21c907dd6e11e2b095afaaa45787d4fe845ec370_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kube-metrics-server-rhel8@sha256:ccd0d9846d6a7109d104789645dce0a3e9cc8dfb0641b44dfc810bac653ac26e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:06608455706f492e1d7bbfbae1e0a545cb66621ed369cef28b42780276c85b3d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:c3ca13ecb86daafcc8266e8b459320401dee826e71e4d99a45eb53ec1249bbe6_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:d0c2b245810b890b12c1a60745e90f79d2f3d5ed6f222dcaa89e470f5edb5257_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/kubevirt-csi-driver-rhel8@sha256:e7f83372ab661ee9f974a1784ba121fb8ed325de75fe807f56f2176622c87c42_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:defea1f2928a0424598235d8f42bf6e084d7baa2f3d77883ba9720b76b5dea10_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:e678250638d259696b6bf1532f12b51e182ea280f78c7505835a5c88e206a680_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:e7cd328b4ffdf2b9811f4ff1f41f90c555384ab12c44acd0f7a07cf40e4ec97e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:e9c36d9874b656c319ac5df0e535c2715f426535868466fab90a7d8e25b5ea14_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:73e6897de0fc9246cf46eb203db3b18346d5b7b681a47a31592477550a151c7d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:772508b2acd3b6ac6573d1a98a126072cfbdc7994ccf9d376e5c228e11ce9d60_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:92cdf682f501fbae76e9eeb834d5d90ac8a6e2c5f252c50aad4907c2add61e48_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/openshift-route-controller-manager-rhel8@sha256:ed4beddd5f649bc9dd64c3a67e638f7f95fcc90ef1dca573ec970ce0dadf3b1b_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:0dd2652c42d7cf4ad1686fe4d2e99322abe07cc7dd5b3b197d3d37758eec692d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:818bbf5c569f1bbe94f4e79faa3c0b85b50303ba6881390f12c5f103036e62c9_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:8c37918837e3dbca230e48c82347ff6501f013a6ee9289841fbc44cecba0f1ba_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:ebffc5e0df51835f8563fd15500e341555dfd386577e493e788b90b1121e6fe1_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-csr-approver-rhel8@sha256:5af0cf592762a0bf06e26ede6c303cfca1d42a9d982e525ff54adf3f6ad80dec_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:234ccdfa4adabcfa7490785bad7108a3c7d622f19cd5b8f4b241dfba96c09be0 (For s390x architecture) The image digest is sha256:b2d858845c618265e67fa36952062ca23a8509824ff9abde5fa04e74808d103d (For ppc64le architecture) The image digest is sha256:7dfd403f5fb3ae023eee7a308673d42d33ee73340aa95dd785a864189ede7aab (For aarch64 architecture) The image digest is sha256:aae6348dbf5138c9bb7fa3ba389adf53dd865969ecf4088f423ade6468615c2e All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem. If using Helm SDK versions prior to 3.14.2, calls to affected functions can use recover to catch the panic. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (30)