Red Hat released security updates across OpenShift Container Platform (OCP) versions 4.12, 4.14, 4.15, and 4.16 to address denial-of-service vulnerabilities in bundled components. Key issues include CVE-2023-39325, the Go net/http/x/net/http2 flaw associated with the HTTP/2 Rapid Reset attack and related to CVE-2023-44487, which lets unauthenticated clients repeatedly create and reset HTTP/2 streams to exhaust server resources. Red Hat rates CVE-2023-39325 as Important, CVSS 7.5, and notes CISA identified active exploitation.
The releases also remediate CVE-2023-47108, in which unbounded-cardinality metrics in OpenTelemetry's otelgrpc component can cause resource exhaustion, alongside other version-specific fixes such as OpenTelemetry otelhttp DoS, word-wrap regular-expression DoS, Python temporary-directory path traversal, XSS, Rekor out-of-memory, and SSH prefix-truncation issues. Organizations should upgrade affected clusters through their supported OCP release channels using the web console or OpenShift CLI; where patching CVE-2023-39325 cannot be immediate, Red Hat recommends reducing the HTTP/2 server stream-concurrency setting as a mitigation.

See which actors are running it and whether you're in range.
100 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2024:6632, a Moderate-impact update for OpenShift Container Platform 4.16.12. The release updated packages and container images to remediate CVE-2023-47108, an otelgrpc denial-of-service issue caused by unbounded-cardinality metrics.
Red Hat issued Moderate-severity advisory RHSA-2024:4118 for Red Hat Ceph Storage 5.3, providing Ceph 16.2.10-266 packages for supported RHEL 8 and 9 systems. The update remediated CVE-2023-39325, CVE-2023-44487, CVE-2023-45142, and CVE-2023-49569.
Red Hat issued Important advisory RHSA-2024:1572 for OpenShift Container Platform 4.12.54, providing updated container images and packages for RHEL 8 and 9 across supported architectures. The release remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 and also listed CVE-2024-1394, CVE-2024-24786, and CVE-2024-28180.
Red Hat issued Important security advisory RHSA-2024:0302 for Kube Descheduler Operator for Red Hat OpenShift 5.0.0 on RHEL 9. Updated operator, descheduler, and bundle container images remediated HTTP/2 Rapid Reset denial-of-service flaws CVE-2023-44487 and CVE-2023-39325.
Red Hat issued Moderate advisory RHSA-2024:0269 for Run Once Duration Override Operator 1.1.0 for Red Hat OpenShift on RHEL 9. The update remediated CVE-2023-44487, CVE-2023-39325, CVE-2023-39326, and CVE-2023-45287 in the operator's container images.
Red Hat issued Important advisory RHSA-2024:0946 for OpenShift Container Platform 4.13.35, supplying updated packages and release images for RHEL 8 and 9 across supported architectures. The update remediated Go HTTP/2 Rapid Reset denial-of-service flaw CVE-2023-39325, associated with CVE-2023-44487, alongside additional listed vulnerabilities.
Red Hat issued Important advisory RHSA-2023:7200 for Red Hat build of MicroShift 4.15.0 on RHEL 9 for x86_64 and ARM64. The RPM update remediated Go flaws CVE-2023-39325, CVE-2023-39326, and CVE-2023-45287, and administrators were instructed to install the latest MicroShift 4.15 RPMs.
Red Hat issued RHSA-2023:7198 for OpenShift Container Platform 4.15.0, providing updated container images, bug fixes, enhancements, and security fixes for supported RHEL 8 and 9 architectures. The Important-impact update remediated multiple issues, including CVE-2023-39325 and CVE-2023-44487 HTTP/2 Rapid Reset flaws, and advised customers to upgrade through their release channel.
Red Hat issued Important advisory RHSA-2024:0682 for OpenShift Container Platform 4.11.58 on RHEL 8 across supported architectures. The updated packages and container images remediated the Go HTTP/2 Rapid Reset flaw CVE-2023-39325, incomplete Rapid Reset fix CVE-2023-6596, and runc file-descriptor leak CVE-2024-21626.
Red Hat issued Important security advisory RHSA-2024:0664 for OpenShift Container Platform 4.12.49, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated Go HTTP/2 Rapid Reset flaw CVE-2023-39325, referenced CVE-2023-44487, and fixed several OpenShift operational defects.
Red Hat issued Important-security-impact advisory RHSA-2024:0484 for OpenShift Container Platform 4.13.31, providing updated container images for RHEL 8 and 9 across supported architectures. The update remediated Go HTTP/2 Rapid Reset flaw CVE-2023-39325, associated with CVE-2023-44487, updated Kubernetes to 1.26.13, and included SELinux, networking, monitoring, and other operational fixes.
Red Hat issued Important advisory RHSA-2024:0485 for OpenShift Container Platform 4.12.48 container images on RHEL 8 and 9. The update remediated CVE-2023-6596, an incomplete prior fix for HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with CVE-2022-41723, CVE-2022-32190, and CVE-2023-3978.
Red Hat issued Important security advisory RHSA-2024:0306 for OpenShift Container Platform 4.11.57 container images on RHEL 8 across x86_64, ppc64le, s390x, and aarch64. The update remediated the Go HTTP/2 Rapid Reset denial-of-service flaw CVE-2023-39325, associated with CVE-2023-44487, and included additional CVE fixes and product enhancements.
Red Hat issued Important security advisory RHSA-2024:0198 for OpenShift Container Platform 4.12.47, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated the Go HTTP/2 Rapid Reset flaw CVE-2023-39325 and HPACK decoder quadratic-complexity flaw CVE-2022-41723, and corrected an authorization issue that could allow user impersonation without the required role binding.
Red Hat issued Important-security-impact advisory RHSA-2024:0050 for OpenShift Container Platform 4.14.8, providing updated container images with bug fixes and enhancements for supported RHEL 8 and 9 architectures. The update remediated the Go HTTP/2 Rapid Reset denial-of-service flaw CVE-2023-39325, referenced CVE-2023-44487, and addressed the OpenTelemetry otelhttp denial-of-service flaw CVE-2023-45142.
Red Hat issued Important security advisory RHSA-2023:7827 for OpenShift Container Platform 4.13.27, updating packages and container images for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 and corrected a user-impersonation authorization issue, along with several operational defects.
Red Hat issued Important security advisory RHSA-2023:7823 for OpenShift Container Platform 4.12.46, providing updated packages and container images for RHEL 8 and 9 on supported architectures. The update remediated Go HTTP/2 Rapid Reset flaw CVE-2023-39325 and HPACK decoder quadratic-complexity flaw CVE-2022-41723, and updated Kubernetes to 1.25.16.
Red Hat issued Important security advisory RHSA-2024:1454 for OpenShift Container Platform 4.13.38, providing updated packages and container images for supported RHEL 8 and 9 architectures. The update remediated the Go HTTP/2 Rapid Reset flaw CVE-2023-39325, associated with CVE-2023-44487, and updated Kubernetes to version 1.26.14.
Red Hat issued Important security advisory RHSA-2023:7610 for OpenShift Container Platform 4.12.45, providing updated packages and images for RHEL 8 and 9 architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with the python-werkzeug resource-consumption denial-of-service vulnerability CVE-2023-46136.
Red Hat issued Important security advisory RHSA-2023:7475 for OpenShift Container Platform 4.13.24, providing updated container images and packages for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset denial-of-service flaws CVE-2023-44487 and CVE-2023-39325 and included additional non-security bug fixes.
Red Hat issued Important advisory RHSA-2023:7470 for OpenShift Container Platform 4.14.4, providing updated container images and packages for RHEL 8 and 9. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, as well as the OpenTelemetry otelhttp denial-of-service flaw CVE-2023-45142.
Red Hat issued Important advisory RHSA-2023:7469 for OpenShift Container Platform 4.14.4, providing updated RPM packages for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 and the OpenTelemetry otelhttp denial-of-service flaw CVE-2023-45142.
Red Hat issued Important advisory RHSA-2023:7555 for OpenShift API for Data Protection 1.3.0 on RHEL 9. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus the OpenTelemetry otelhttp denial-of-service vulnerability CVE-2023-45142.
Red Hat issued Important security advisory RHSA-2023:7315 for OpenShift Container Platform 4.14.3, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus the Go HTML cross-site-scripting flaw CVE-2023-3978.
Red Hat issued Important advisory RHSA-2023:7323 for OpenShift Container Platform 4.13.23 container images on RHEL 8 and 9. The update remediated Rekor out-of-memory flaw CVE-2023-30551 and HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487, along with additional security and operational fixes.
Red Hat issued Important security advisory RHSA-2023:6894 for OpenShift Container Platform 4.12.44, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset denial-of-service flaws CVE-2023-44487 and CVE-2023-39325 and included Multus, Insights, permissions, and ConfigMap-related fixes.
Red Hat issued Important security advisory RHSA-2023:7325 for OpenShift Container Platform 4.13.23, supplying updated RPM packages for RHEL 8 and 9 across x86_64, ppc64le, s390x, and aarch64. The update remediated HTTP/2 Rapid Reset flaw CVE-2023-44487 and the related Go net/http and x/net/http2 flaw CVE-2023-39325; associated container images were referenced through RHSA-2023:7323.
Red Hat issued Product Enhancement Advisory RHEA-2023:7327 for Red Hat 3scale API Management 2.13.7 container images on RHEL 7 and 8. The advisory associated the release with CVE-2023-39325 and CVE-2023-44487, among other CVEs, but listed no individual fixes.
Red Hat issued Important security advisory RHSA-2023:6842 for OpenShift Container Platform 4.12.43, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated node-role-label modification flaw CVE-2023-5408 and HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487.
Red Hat issued Important advisory RHSA-2023:6837 for OpenShift Container Platform 4.14.2 container images on RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, Go HTML cross-site-scripting flaw CVE-2023-3978, and additional listed vulnerabilities.
Red Hat issued Important security advisory RHSA-2023:6840 for OpenShift Container Platform 4.14.2 packages on RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go net/http, crypto/tls, and html/template vulnerabilities including CVE-2023-29406, CVE-2023-29409, CVE-2023-39318, CVE-2023-39319, CVE-2023-39321, and CVE-2023-39322.
Red Hat issued Important advisory RHSA-2023:6269 for cert-manager Operator for Red Hat OpenShift 1.12.1 on x86_64. The container-image update remediated HTTP/2 Rapid Reset vulnerabilities CVE-2023-44487 and CVE-2023-39325; automatic installation plans upgraded automatically, while manual plans required administrator approval.
Red Hat issued Important security advisory RHSA-2023:6279 for cert-manager Operator for Red Hat OpenShift 1.11.5 on x86_64. The update remediated the Go HTTP/2 Rapid Reset flaw CVE-2023-39325 and the Go crypto/tls large-RSA-key verification denial-of-service flaw CVE-2023-29409.
Red Hat issued Important security advisory RHSA-2023:6846 for OpenShift Container Platform 4.13.22, providing updated container images and packages for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset denial-of-service flaws CVE-2023-44487 and CVE-2023-39325 and included Multus configuration hardening changes.
Red Hat issued Important security advisory RHSA-2023:6817 for OpenShift Virtualization 4.14.0 images for Red Hat Container Native Virtualization 4.14 on RHEL 9 x86_64 and aarch64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus MongoDB Go driver, Go TLS and multipart, and containerd vulnerabilities.
Red Hat issued Important security advisory RHSA-2023:6272 for OpenShift Container Platform 4.11.53, providing updated container images for RHEL 8 on supported architectures. The release remediated HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487, addressed CVE-2023-3153, and fixed several operational issues including a CoreDNS EndpointSlice panic.
Red Hat issued Important advisory RHSA-2023:6786 for Fence Agents Remediation Operator 0.2.1 in Red Hat OpenShift Workload Availability 1 on RHEL 8 x86_64. Updated operator container images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with other listed CVEs.
Red Hat issued Important security advisory RHSA-2023:6276 for OpenShift Container Platform 4.12.42, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated the Go HTTP/2 Rapid Reset flaw CVE-2023-39325, referenced CVE-2023-44487, and included CVE-2023-3153 plus operational bug fixes.
Red Hat issued Important advisory RHSA-2023:6298 for OpenShift Serverless Client kn 1.30.2 on RHEL 8 for x86_64, ppc64le, and s390x. Updated openshift-serverless-clients 1.9.2-4.el8 RPMs remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go Host-header sanitization and large-RSA TLS verification flaws CVE-2023-29406 and CVE-2023-29409.
Red Hat issued Moderate-security advisory RHSA-2023:6296 for OpenShift Serverless 1.30.2 on RHEL 8 for x86_64, ppc64le, and s390x systems supporting OpenShift Container Platform 4.11 through 4.13. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go TLS and Host-header flaws CVE-2023-29409 and CVE-2023-29406.
Red Hat issued Important advisory RHSA-2023:6126 for OpenShift Container Platform 4.12.41, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated Go HTTP/2 Rapid Reset flaw CVE-2023-39325, referenced CVE-2023-44487, and included additional non-security bug fixes.
Red Hat issued Important security advisory RHSA-2023:6251 for OpenShift Virtualization 4.11.7 images for Red Hat Container Native Virtualization 4.11 on RHEL 7 and 8 x86_64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, the HPACK decoder flaw CVE-2022-41723, and additional listed vulnerabilities.
Red Hat issued Important security advisory RHSA-2023:6235 for OpenShift Virtualization 4.13.5 images, covering Container Native Virtualization 4.13 deployments on supported RHEL 7, 8, and 9 architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, the HPACK decoder flaw CVE-2022-41723, and other listed vulnerabilities.
Red Hat issued Important advisory RHSA-2023:6154 for Secondary Scheduler Operator for Red Hat OpenShift 1.2.0 on RHEL 8 x86_64. Updated operator images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with Go html/template and crypto/tls vulnerabilities including CVE-2023-39318, CVE-2023-39319, CVE-2023-39321, and CVE-2023-39322.
Red Hat issued Important security advisory RHSA-2023:5009 for OpenShift Container Platform 4.14.0, providing updated RPM packages for RHEL 8 and 9 across supported architectures; associated container images were provided through RHSA-2023:5006. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, as well as Go, OVN, SciPy, goproxy, FIPS-mode, and OpenShift vulnerabilities.
Red Hat issued Important-security advisory RHSA-2023:5007 for OpenShift Container Platform 4.14.0, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus vulnerabilities including mongo-go-driver CVE-2021-20329, HPACK decoder CVE-2022-41723, Go HTML XSS CVE-2023-3978, and goproxy DoS CVE-2023-37788.
Red Hat issued Important advisory RHSA-2023:5006 for OpenShift Container Platform 4.14.0, supplying updated packages and container images for RHEL 8 and 9 across supported architectures. The release remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with numerous OpenShift and bundled-component vulnerabilities.
Red Hat issued Important-security advisory RHSA-2023:6200 for Multicluster Engine for Kubernetes 2.1.9 General Availability release images. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, as well as Go crypto/tls and html/template vulnerabilities, for supported x86_64, aarch64, ppc64le, and s390x deployments.
Red Hat issued Important security advisory RHSA-2023:6161 for Migration Toolkit for Containers 1.7.14 on RHEL 8 x86_64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go Host-header, TLS, QUIC, and html/template vulnerabilities including CVE-2023-29406, CVE-2023-29409, CVE-2023-39318, CVE-2023-39319, CVE-2023-39321, and CVE-2023-39322.
Red Hat issued Important advisory RHSA-2023:6130 for OpenShift Container Platform 4.13.19, providing updated container images and packages for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487, as well as CVE-2023-5408 involving modification of node-role labels.
Red Hat issued Important advisory RHSA-2023:5933 for Secondary Scheduler Operator for Red Hat OpenShift 1.1.3 on RHEL 8 x86_64. Updated bundle and operator container images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go Host-header sanitization and TLS certificate-chain verification flaws CVE-2023-29406 and CVE-2023-29409.
Red Hat issued Important advisory RHSA-2023:5947 for Run Once Duration Override Operator 1.0.1 on Red Hat OpenShift for RHEL 8 x86_64. Updated operator container images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, alongside multiple Go html/template, net/http, crypto/tls, and crypto/internal/nistec vulnerabilities.
Red Hat issued Important security advisory RHSA-2023:5896 for OpenShift Container Platform 4.12.40, providing updated packages and container images for RHEL 8 and 9 across x86_64, s390x, ppc64le, and aarch64. The update remediated the HTTP/2 Rapid Reset denial-of-service vulnerability CVE-2023-44487 and included CVE-2023-38545, CVE-2023-38546, and an OCP rendezvous-host configuration fix.
Red Hat issued Important security advisory RHSA-2023:6115 for OpenShift API for Data Protection 1.1 on RHEL 8, providing updated container images for ppc64le, s390x, and x86_64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go net/http, crypto/tls, and html/template vulnerabilities including CVE-2023-29406, CVE-2023-29409, CVE-2023-39318, CVE-2023-39319, CVE-2023-39321, and CVE-2023-39322.
Red Hat issued Important security advisory RHSA-2023:6122 for Advanced Cluster Management for Kubernetes 2.8.3 General Availability images on RHEL 8. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, Go html/template and crypto/tls vulnerabilities CVE-2023-39318, CVE-2023-39319, CVE-2023-39321, and CVE-2023-39322, and additional listed CVEs.
Red Hat issued Important security advisory RHSA-2023:5902 for OpenShift Container Platform 4.13.18, providing updated packages and container images for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset vulnerability CVE-2023-44487 and referenced the related Go flaw CVE-2023-39325.
Red Hat issued Important security advisory RHSA-2023:6085 for OpenShift Distributed Tracing 2.9, providing updated Jaeger, OpenTelemetry, Tempo, and operator container images for x86_64, ppc64le, and s390x deployments. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go Host-header, TLS, QUIC post-handshake, and html/template vulnerabilities.
Red Hat issued Important-security advisory RHSA-2023:5542 for Logging Subsystem 5.5.17 for Red Hat OpenShift on RHEL 8. The container-image update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with tough-cookie prototype-pollution vulnerability CVE-2023-26136.
Red Hat issued Important security advisory RHSA-2023:6041 for Self Node Remediation Operator 0.7.1 in Red Hat OpenShift Workload Availability 1 for RHEL 8 x86_64. Updated operator and bundle container images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325.
Red Hat issued Important security advisory RHSA-2023:6039 for Node Maintenance Operator 5.0.1 in Red Hat OpenShift Workload Availability 1 on RHEL 8 x86_64. Updated operator, bundle, and must-gather container images remediated HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487.
Red Hat issued Important advisory RHSA-2023:6031 for Cryostat 2 on RHEL 8, providing updated x86_64 container images and related operator, reporting, Grafana dashboard, and JFR datasource artifacts. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus CVE-2023-3978 and multiple Go net/http and crypto/tls vulnerabilities.
Red Hat issued Important security advisory RHSA-2023:5530 for Logging Subsystem 5.7.7 for Red Hat OpenShift on RHEL 8. Updated logging container images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go Host-header sanitization and large-RSA TLS verification flaws CVE-2023-29406 and CVE-2023-29409.
Red Hat issued Important security advisory RHSA-2023:5976 for Service Telemetry Framework 1.5.2 on Red Hat OpenStack 1 for RHEL 8 x86_64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus Go TLS, Host-header sanitization, P-256 scalar-processing, memory-exhaustion, and large-RSA-key verification issues.
Red Hat issued Important security advisory RHSA-2023:5982 for Red Hat Satellite Client 6 on RHEL 6, 7, 8, and 9. The update remediated HTTP/2 flaws CVE-2023-44487, CVE-2023-39325, and CVE-2022-41717, OpenSSL c_rehash command-injection flaws CVE-2022-1292 and CVE-2022-2068, and two Satellite client operational defects.
Red Hat issued Important security advisory RHSA-2023:5980 for Red Hat Satellite and Satellite Capsule 6.11.5.6 on RHEL 7 and RHEL 8 x86_64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 in yggdrasil-worker-forwarder, plus Foreman arbitrary-code-execution, ruby-git code-injection, and OpenSSL c_rehash command-injection vulnerabilities.
Red Hat issued Important security advisory RHSA-2023:5970 for collectd-libpod-stats 1.0.5-6.el8ost in Red Hat OpenStack Platform 17.1.1 for RHEL 8 x86_64. The update remediated HTTP/2 Rapid Reset vulnerabilities CVE-2023-44487 and CVE-2023-39325.
Red Hat issued Important security advisory RHSA-2023:5974 for Network Observability 1.4.0 on RHEL 9. The container-image update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, along with multiple Go net/http, crypto/tls, and html/template vulnerabilities including CVE-2023-29406, CVE-2023-29409, CVE-2023-39321, and CVE-2023-39322.
Red Hat issued Important security advisory RHSA-2023:5541 for Logging Subsystem 5.6.12 for Red Hat OpenShift on RHEL 8. The updated images remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, tough-cookie prototype pollution CVE-2023-26136, and Go flaws CVE-2023-29406 and CVE-2023-29409.
Red Hat issued Important security advisory RHSA-2023:5931 for the Red Hat Satellite 6.13.5 asynchronous update, affecting Satellite 6.13, Satellite Capsule 6.13, and associated RHEL 8 x86_64 packages. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 in Yggdrasil-worker-forwarder, along with Foreman, GitPython, ruby-git, Django, and OpenSSL vulnerabilities.
Red Hat issued Important advisory RHSA-2023:5677 for OpenShift Container Platform 4.12.39, providing updated release images for RHEL 8 and 9 on x86_64, s390x, ppc64le, and aarch64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, updated Kubernetes to 1.25.14, and fixed multiple OpenShift operational defects.
Red Hat issued Important advisory RHSA-2023:5679 for OpenShift Container Platform 4.12.39, supplying updated packages for RHEL 8 and 9 across x86_64, ppc64le, s390x, and aarch64. The update remediated HTTP/2 Rapid Reset vulnerability CVE-2023-44487 and the related Go HTTP/2 flaw CVE-2023-39325.
Red Hat issued Important security advisory RHSA-2023:5717 for OpenShift Container Platform 4.11.52 RPM packages on RHEL 8 for x86_64, ppc64le, s390x, and aarch64. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325; associated container images were provided through RHSA-2023:5697.
Red Hat issued Important advisory RHSA-2023:5697 for OpenShift Container Platform 4.11.52 container images on RHEL 8 across supported architectures. The update remediated CVE-2023-2253 in distribution/distribution and HTTP/2 denial-of-service flaws CVE-2023-39325 and CVE-2023-44487.
Red Hat issued Important advisory RHSA-2023:5835 for rhc-worker-script 0.5-1.el7_9 on RHEL 7 x86_64 variants. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 in the Remote Host Configuration worker used by Red Hat Insights.
Red Hat issued Moderate security advisory RHSA-2023:5864 for Grafana 7.5.11-4.el8_6 across RHEL 8.6 extended-life-cycle, extended-update-support, AUS, TUS, and SAP-support channels. The update remediated HTTP/2 Rapid Reset vulnerabilities CVE-2023-44487 and CVE-2023-39325 for x86_64, s390x, ppc64le, and aarch64 systems.
Red Hat issued Moderate-severity advisory RHSA-2023:5863 for Grafana on RHEL 8, supplying grafana-7.5.15-5.el8_8 for supported architectures and applicable update-service variants. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487.
Red Hat issued bug-fix advisory RHBA-2023:5782 updating rhel8/go-toolset and ubi8/go-toolset container images for RHEL 8. The images incorporate RHSA-2023:5721 security fixes for HTTP/2 Rapid Reset vulnerabilities CVE-2023-44487 and CVE-2023-39325 across x86_64, aarch64, ppc64le, and s390x.
Red Hat issued Important security advisory RHSA-2023:5672 for OpenShift Container Platform 4.13.17, supplying updated container images and packages for RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, as well as HPACK-decoding quadratic-complexity flaw CVE-2022-41723.
Red Hat issued Important security advisory RHSA-2023:5719 for go-toolset-1.19 and go-toolset-1.19-golang in Red Hat Developer Tools 1 on RHEL 7 Server and Workstation systems. The updated packages remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 across x86_64, s390x, and ppc64le platforms.
Red Hat issued Important advisory RHSA-2023:5738 for RHEL 9, updating go-toolset and golang packages to version 1.19.13-1.el9_2 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus the Go crypto/tls large-RSA-key verification denial-of-service flaw CVE-2023-29409.
Red Hat logged Bug 2242803 for CVE-2023-44487, the HTTP/2 Rapid Reset denial-of-service flaw in which attackers rapidly create and cancel streams to consume server resources. The issue was reportedly exploited in the wild from August through October 2023, and Red Hat began tracking affected HTTP/2 servers and libraries across its product portfolio.
Red Hat issued RHSA-2023:5463 to update the RHEL 8 python3.11 package for CVE-2023-40217, an ssl.SSLSocket flaw that can bypass TLS client authentication in certain server-side mTLS scenarios. Red Hat rated the issue Important (CVSS 8.6) and stated that exploitation could permit modification or deletion of certificate-protected resources, but not disclosure of confidential data.
Red Hat created EPEL and Fedora tracking bugs for CVE-2023-39319, in which Go html/template improperly handled "<script", "<!--", and "</script" inside JavaScript literals, potentially causing premature script-context termination and improperly escaped template actions. Red Hat subsequently issued fixes across RHEL, OpenShift, OpenStack, and Kubernetes-management products.
Red Hat tracked CVE-2023-37788, a denial-of-service vulnerability in goproxy 1.1 reported by Vipul Nair on July 20, 2023. Red Hat addressed it through advisories for OpenShift GitOps 1.10, OpenShift Container Platform 4.14 and 4.15, RHODF 4.14, and Red Hat OpenStack Platform 16.2; Fedora also tracked the issue.
CVE-2023-29406 (GO-2023-1878) affects Go's HTTP/1 client, which insufficiently validated Host-header values, allowing crafted Request.Host or Request.URL.Host values to inject HTTP headers or entire requests. The fix rejects requests containing invalid Host values; Avinash Hanwate described the issue on July 12, 2023.
Red Hat released the Important-impact OpenShift Container Platform 4.15.5 update with container-image fixes for CVE-2023-44487 and CVE-2023-39325 HTTP/2 Rapid Reset denial-of-service issues, as well as CVE-2023-47108 in otelgrpc. The update applied to OCP 4.15 deployments on RHEL 8 and 9 across x86_64, s390x, ppc64le, and aarch64 architectures.
Red Hat issued Important advisory RHSA-2024:1037 for OpenShift Container Platform 4.13.36, providing updated container images for supported RHEL 8 and 9 architectures. The update remediated Go HTTP/2 Rapid Reset denial-of-service flaw CVE-2023-39325, associated with CVE-2023-44487, and addressed storage, networking, SELinux, CRI-O, bare-metal provisioning, and console defects.
Red Hat issued Important-security-impact advisory RHSA-2024:0193 for OpenShift Container Platform 4.13.29, providing container images for supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325 and fixed mongo-go-driver input-validation flaw CVE-2021-20329.
Red Hat issued RHSA-2023:7682, an Important security and bug-fix update providing revised OpenShift Container Platform 4.14.6 container images for RHEL 8 and 9. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, plus the OpenTelemetry otelhttp denial-of-service flaw CVE-2023-45142.
Red Hat released OpenShift Container Platform 4.14.6 with updated RPM packages and images fixing CVE-2023-26115, CVE-2023-45142, and the otelgrpc denial-of-service flaw CVE-2023-47108. Container-image updates were provided separately through RHSA-2023:7682.
Red Hat issued Important security advisory RHSA-2023:7687 for OpenShift Container Platform 4.13.26 on RHEL 8 and 9 across supported architectures. The update remediated HTTP/2 Rapid Reset flaws CVE-2023-44487 and CVE-2023-39325, updated Kubernetes to 1.26.11, and included additional operational bug fixes.
Red Hat released an Important security and bug-fix update for OpenShift Container Platform 4.13.25 on RHEL 8 and 9 across supported architectures. The updated packages and container images remediate Go HTTP/2 Rapid Reset vulnerability CVE-2023-39325 and include additional product bug fixes.
Red Hat released the Critical-security-impact OpenShift Container Platform 4.12.51 update for RHEL 8 and 9 across supported architectures. Updated packages and container images remediate CVE-2023-49569, a go-git path-traversal and remote-code-execution issue, CVE-2023-49568, a go-git denial-of-service flaw, and the Go HTTP/2 Rapid Reset flaw CVE-2023-39325.
Red Hat released Important advisory RHSA-2023:7599 for OpenShift Container Platform 4.14.5, providing updated packages and container images for RHEL 8 and 9 on supported architectures. The update remediated the HTTP/2 Rapid Reset flaws CVE-2023-39325 and CVE-2023-44487, along with the OpenTelemetry otelhttp denial-of-service vulnerability CVE-2023-45142.
Red Hat issued Important-rated advisory RHSA-2023:6257 for OpenShift Container Platform 4.13.21, providing updated container images for RHEL 8 and 9 across supported architectures. The update remediated the Go HTTP/2 Rapid Reset flaw CVE-2023-39325, referenced CVE-2023-44487, and addressed multiple operational defects.
CVE-2021-20329 is an improper input-validation flaw in MongoDB Go Driver BSON marshalling: crafted cstring input in Go objects can inject additional fields into a marshalled BSON document. The issue affects versions through 1.5.0 and was addressed in version 1.5.1; Red Hat subsequently issued fixes across affected OpenShift Container Platform, OpenShift Service Mesh, and RHEL 9 CNV streams.
CVE-2022-41723 was documented as a denial-of-service flaw in Go's net/http HTTP/2 HPACK decoder, where a malicious HTTP/2 stream can trigger quadratic CPU consumption with a small number of requests. The issue was fixed for manually configured HTTP/2 users in golang.org/x/net/http2 version 0.7.0, with Fedora, EPEL, and Red Hat tracking or issuing fixes across affected Go-based products.
Red Hat tracked CVE-2023-26136, a tough-cookie prototype-pollution vulnerability affecting versions before 4.1.3 when CookieJar is used with rejectPublicSuffixes=false. Red Hat issued fixes for affected OpenShift Logging, Advanced Cluster Management, multicluster engine for Kubernetes, JBoss EAP, Migration Toolkit for Containers, and OpenShift Data Foundation releases.
Upstream Go remediated CVE-2023-39325 in Go 1.21.3 and Go 1.20.10. Red Hat also confirmed that the fix had been backported into its go1.19.13-2-openssl-fips source archive and issued fixes across RHEL and downstream product lines.
CVE-2023-39325 was documented as a Go net/http and golang.org/x/net/http2 flaw in which an unauthenticated HTTP/2 client can repeatedly create and reset streams, consuming server resources and causing denial of service. Red Hat linked it to the HTTP/2 Rapid Reset attack and CVE-2023-44487, rated it Important with a CVSS 7.5 score, and stated that CISA had identified active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
50 references tracked. Mallory keeps watching after this page renders.
quay.io
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecatalog.redhat.com
Open sourcenginx.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.