RHSA-2024:3327HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.15.15 security update

Published
May 29, 2024
Last Modified
September 18, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-1135 — python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers CVE-2024-28180 — jose-go: improper handling of highly compressed data

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:2092c07fea086f20b85d3c51cdbf2706ec35b8cb57ac9259513c860095ffdb82_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:78a1c7ce56a49f629e064d16e6ceda0165358964e1a0bf6bf2d29119aedd7818_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:95c0080cf33f38389c299d1a368fc3b134372cc2267eb55756463b54a4929bf2_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/cloud-network-config-controller-rhel8@sha256:9dced2ee6ff361474f92d1c06609ae57120405b47f395ae0f02af2dfaecfed60_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:10ad4e1cabaddc881a7deda50448e4885382ca6e379b117a3cf0fd8683f6f3aa_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:934af754e2fbc8ed5deb7c4b22299c6c7b4504e6d8d9fd50fc3ad374616d70a9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:ae34b1c2137ae680d77ca436c347e6eb02242d6404fb6e776b27d6fd6e141b20_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/driver-toolkit-rhel9@sha256:e65a53bf2078a9bd537de950d970726685e1e468dbb1bfc337fed03507574bb9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:09e5fd03e871289e035ceb291d594a9267576ae721de3583ab8642736c6f610d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:104945773fd5560b3d253eaf18fa2c06a3b17508d8a65896ce31f8670a97e841_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:60f61fd5113dac2d93ccd32ef7c897f5a1c4fec0f531502197405e5bfbdabe9d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/network-tools-rhel8@sha256:fcee797dd40ea3806f870e3ac4caab140ef270a32b2d73b27a8b1e375efe14f8_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:263c33ee5024370a0f48b9c828a66e2aa2f01c249b0b4a27c1e965afa0942614_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:5b97ddc6cc47aafe9aad6278a1f315ac6618b920ba4062181ccefde8599ab2fc_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:74ee4776b35f9bad750ad66a515cfa9517b2bb5b29e57f5d4b44a35a7c8681f0_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/oc-mirror-plugin-rhel9@sha256:c03b0fa2085e64c0399fb4e1078fcb8e8425cbcc5e3a2dbca3c63acfe7c9a332_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:165e537963db3d3aa4de3fac4d2bcbe803bb62c5bd2103544f62cbc896a4c4e3_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:9fcae2df12ef06dbfce84332769941a416a241fb45785624c006ed79412766de_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:c3b322639065df9f666d5024ec3401b91ef3954c6eeef6665bed9935581149c7_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-api-server-rhel8@sha256:d728cce7ab747336286bf25aa11aefd5115ead41c9d8e7538b69b1d10a63cbc6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:3223a11ca7dad39ee64fbd075eb85d9914b5f6d73c7d11b3b9307407dc7a2150_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:69496773869ac8dc4f371da5f9bab3e446928392ed18e5d70e49caa0febf4847_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:b9b4d11e0e9289b1f1c4e510213fb13dbbbb36e495d22a30207002e8775dd8df_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-node-agent-rhel9@sha256:e38b6ab62fa6bc8ab5811a935eedd945b9a1b5468f99a7a051e841e6114d7149_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-utils-rhel9@sha256:074599365022a1740a585b18d5c5c024b3648cfaffb8234e9a18a9f61922d8fa_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-utils-rhel9@sha256:733693fab2cf41b88cfb49065e6e62724d672a2667b6f5d5446c3a0f77f32b46_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-utils-rhel9@sha256:c8e632b1e7d8f20dc489d2359564c664f208eaedfaa722d3b4856a4014e68ebb_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-agent-installer-utils-rhel9@sha256:f6142cb5d3db923a071ba44b74e61aec3435e2d071d6b3ca65692f25178c15f3_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • openshift4/ose-alibaba-cloud-controller-manager-rhel9@sha256:8e8f8d5e88b20da7aa70a14abb4bda1db2866f595ae7018d406267a214b191a5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:bb1182cd9001d6811dea8c5823235c17b9a316cce3bb13c51325250c14b46787 (For s390x architecture) The image digest is sha256:406246b2588868ce440434d1b3a4deed88c22085612eb1bf7b8faddc5a37d02a (For ppc64le architecture) The image digest is sha256:277ef1089fd5495f728676929a365f6e2cf6bd739855964e27b61e74377f1119 (For aarch64 architecture) The image digest is sha256:092ed599a300fb7985b94a5d9f108848d0ef0008399068e1cd207ea9e948d6d5 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.15/updating/updating_a_cluster/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (27)