Red Hat tracked two vulnerabilities in the Go-based Gin web framework: CVE-2023-29401 (GO-2023-1737), in which unsanitized Context.FileAttachment filename input can manipulate the Content-Disposition header and alter a downloaded file’s apparent name or extension; and CVE-2023-26125, in which a crafted X-Forwarded-Prefix header can enable cache poisoning when applications incorporate that header into request handling. Gin corrected the issues in versions 1.9.1 and 1.9.0, respectively.
Red Hat shipped fixes through product advisories, including Migration Toolkit for Containers (MTC) 1.7.11 for RHEL 8 x86_64 under RHSA-2023:4293, which also addressed Go HTTP/2 HPACK-decoding and HTML-template issues. Affected deployments should update MTC container images and upgrade OpenShift Container Platform through the supported release channel; Red Hat also tracked remediation for MTC 1.7, OpenShift Container Platform 4.13/4.14, and Migration Toolkit for Applications 6.2 on RHEL 8 and 9.

See affected versions and whether adversaries are exploiting it.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:3494 for OpenShift Container Platform 4.13.43. The update remediated the denial-of-service risk from quadratic-complexity HPACK decoding in CVE-2022-41723.
RHSA-2024:0948 released OpenShift Container Platform 4.13.35 with updated packages and images that fixed CVE-2022-41723 in Go net/http and golang.org/x/net/http2.
Red Hat issued RHBA-2023:5382, making OpenShift Container Platform 4.13.14 available with updated packages and container images. The bug-fix release updated Kubernetes to 1.26.9 and addressed installation, upgrade, networking, console, storage, and image-management defects as well as 11 listed CVEs.
Red Hat issued RHSA-2023:4731 for OpenShift Container Platform 4.13.10. The Moderate update remediated CVE-2022-41723 and included a Kubernetes 1.26.7 update.
RHSA-2023:4456 released OpenShift Container Platform 4.13.8, including fixes for CVE-2023-3089 affecting FIPS mode and CVE-2022-41723 in Go HTTP/2 HPACK decoding.
RHSA-2023:4293 released Migration Toolkit for Containers 1.7.11 and fixed CVE-2023-29401 in Gin's FileAttachment filename handling, CVE-2023-26125, and several Go vulnerabilities including CVE-2022-41723.
Red Hat Product Security DevOps marked the Red Hat tracking bug for CVE-2023-29401 closed after fixes were issued for affected products.
Red Hat issued RHSA-2023:3614, a Moderate advisory for OpenShift Container Platform 4.13.4. The release addressed CVE-2022-41723, which could cause quadratic-complexity processing during HTTP/2 HPACK decoding.
RHSA-2023:3537 released OpenShift Container Platform 4.13.3, fixing CVE-2022-41723 in Go HPACK decoding, CVE-2023-25173 in containerd supplementary-group handling, and CVE-2023-26054 in BuildKit provenance attestations.
RHSA-2023:3367 released OpenShift Container Platform 4.13.2 with fixes for eight Go vulnerabilities, including denial-of-service flaws in HTTP parsing and HPACK decoding and html/template sanitization issues.
Red Hat issued RHSA-2023:3304, a Moderate advisory releasing OpenShift Container Platform 4.13.1. The update remediated several issues, including CVE-2018-17419, CVE-2021-36157, CVE-2022-41722, and CVE-2022-41723.
Red Hat addressed CVE-2023-29401 for OpenShift Container Platform 4.14 through RHSA-2023:5006 and later listed fixes through RHSA-2024:8235 and RHSA-2024:8697. It also issued RHSA-2024:8688 and RHSA-2024:10813 to address CVE-2023-26125 for OpenShift Container Platform 4.13.
Red Hat issued RHSA-2023:4627 to address CVE-2023-26125 for Migration Toolkit for Applications 6.2 on RHEL 8 and RHEL 9.
Red Hat released OpenShift Container Platform 4.13.9 as a Moderate security and bug-fix update. It addressed CVE-2022-41723 and corrected a weak TLS configuration on port 9447 that permitted TLS 1.0, TLS 1.1, and a weak cipher.
Gin released version 1.9.1 to address CVE-2023-29401, in which Context.FileAttachment did not properly sanitize a caller-controlled filename before constructing the Content-Disposition header.
Gin version 1.9.0 addressed CVE-2023-26125, an improper-input-validation flaw in which a crafted X-Forwarded-Prefix header could potentially enable cache poisoning depending on application and server configuration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.