Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7663 - Security Advisory
Issued:
2023-12-06
Updated:
2023-12-06

RHSA-2023:7663 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift distributed tracing 3.0.0 operator/operand containers

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift distributed tracing 3.0.0

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Release of Red Hat OpenShift distributed tracing provides these changes:

Security Fix(es):

CVE-2023-45142 opentelemetry: DoS vulnerability in otelhttp
CVE-2023-46129 nkeys: xkeys Seal encryption used fixed key for all encryption

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Affected Products

  • Red Hat OpenShift distributed tracing 3 x86_64
  • Red Hat OpenShift distributed tracing for Power, little endian 3 ppc64le
  • Red Hat OpenShift distributed tracing for IBM Z and LinuxONE 3 s390x
  • Red Hat OpenShift distributed tracing for ARM 3 aarch64

Fixes

  • BZ - 2245180 - CVE-2023-45142 opentelemetry: DoS vulnerability in otelhttp
  • BZ - 2246986 - CVE-2023-46129 nkeys: xkeys Seal encryption used fixed key for all encryption
  • TRACING-1805 - Jaeger pod fails on Disconnected cluster with pull errors for registry.redhat.io/openshift4/ose-oauth-proxy:latest
  • TRACING-3217 - [OpenTelemetry] Failed to create route when exposing the OpenTelemetry Collector via CR
  • TRACING-3379 - The pod mutator for the instrumentation injection is run multiple times for the same pod, not allowing it to start
  • TRACING-3510 - Tempo query frontend service should not use internal mTLS when gateway is not deployed
  • TRACING-3523 - Missing Tempo operator images when mirroring images using oc mirror, oc adm catalog mirror
  • TRACING-3555 - [OpenTelemetry Operator] Cannot set image name with image sha in OpenTelemetry collector instance.
  • TRACING-3568 - Investigate tempo reconcile error messages and certificate log spam

CVEs

  • CVE-2007-4559
  • CVE-2023-4641
  • CVE-2023-22745
  • CVE-2023-45142
  • CVE-2023-46129

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

rhosdt/jaeger-agent-rhel8@sha256:f416a0ae5e029eee58e4c02f102e95f80e45402bd86ecd8b0746a2c700f736cf
rhosdt/jaeger-all-in-one-rhel8@sha256:0c763ffe9405b0928dd5916b71486f888ee6f37754e0d3f9feb74b25f617a2cb
rhosdt/jaeger-collector-rhel8@sha256:96235c48cc11499f15d22b4919823a648c73de381abb1506a5f1c40309d10b18
rhosdt/jaeger-es-index-cleaner-rhel8@sha256:de28c8131fa2b6f7fba1b246557c13c4fc294975059c899972bb692c14d30012
rhosdt/jaeger-es-rollover-rhel8@sha256:1cc081f4533b9e2364685bd69d75f531cf2e642a725ad4bdf2ba8391e0e25f3e
rhosdt/jaeger-ingester-rhel8@sha256:4975a52d66395af440ff4148bd93d787ab3b16787025e7e2336074aa27761120
rhosdt/jaeger-operator-bundle@sha256:925087209f7c167f02573a1941a2abd401a99061282be964e59d24271d5ed998
rhosdt/jaeger-query-rhel8@sha256:df0b1ae25db7de9281aea724f4358aabd3fab116584545edadedc1324282285c
rhosdt/jaeger-rhel8-operator@sha256:80270108087a60d63e530ce0adfea1786135e50c5c7d4e4bdba6136a3065608a
rhosdt/opentelemetry-collector-rhel8@sha256:919ce669fd6238e3b6ffb91b2913bd9fd6b67e9d7e88ab968ea533d61289cd16
rhosdt/opentelemetry-operator-bundle@sha256:b5d5510474675de5f836b205bf7e2d9c3c7d5b58a4499cff074bcd6142bcea6c
rhosdt/opentelemetry-rhel8-operator@sha256:9084499abcc669a5cf2b127558f511fd7f3bd84dcbb22dd3aa63c696d377d3d3
rhosdt/tempo-gateway-opa-rhel8@sha256:4a38500536aa79127781e6e18759a22d3d2f1c455a922c29563d9f9163f1c68e
rhosdt/tempo-gateway-rhel8@sha256:910096f8781fcd9048810c8c15754e77f094f567d74d60677e5beefe5b94d528
rhosdt/tempo-operator-bundle@sha256:6dcb68ace16c0e82ce12e808f3ac4886ef663bd76e38eb2ce8c3a1fa65e6de68
rhosdt/tempo-query-rhel8@sha256:28f5c9a3ad4551bd0445b1a637151e3f112706637f0bfdc3dc4968648b8f404f
rhosdt/tempo-rhel8@sha256:cf49ba228d39dea353c61d2780014f1c0d8e986e78ac21c9389f7f4482132f30
rhosdt/tempo-rhel8-operator@sha256:59084d728b66eda4cadf932d89a560cc1e9c6485374cf911e7065799ceec5f89

ppc64le

rhosdt/jaeger-agent-rhel8@sha256:e9ecc93a6226cb73a9bf7402906586e24a772269a9bff5365e5c67caa080658d
rhosdt/jaeger-all-in-one-rhel8@sha256:469143ab1b29cc73db41e7c2234d4906ee5eb4e1179431a35cf5728361d3ede4
rhosdt/jaeger-collector-rhel8@sha256:f0cf2e3c77374cb318bf8b69fa6bd8c1478c967598fc2a59174e0955d220c36e
rhosdt/jaeger-es-index-cleaner-rhel8@sha256:11a13b30564efabdb7dd6c55ed839c2bba54b220d8d5c39948df76a433fd50fb
rhosdt/jaeger-es-rollover-rhel8@sha256:6a9f07800179639aaf394b1e2b00ec6ea2d9c698329c40c9e9e7fc805c9250d3
rhosdt/jaeger-ingester-rhel8@sha256:977fca15a589e7d6c0575abf6224387da5edb1ff3e09c2f90e6c4f2fa20227d7
rhosdt/jaeger-operator-bundle@sha256:110ce786fa2f997331c889d314fd136b68683a00032667bef797cab27d20e32d
rhosdt/jaeger-query-rhel8@sha256:78e660916be15db85341c6b37660193d603320acc1b43073083befd4eb386b1d
rhosdt/jaeger-rhel8-operator@sha256:e5ec90c39ffb1a622f5def1012041507a082b04c6ec05fc55597329cce74c844
rhosdt/opentelemetry-collector-rhel8@sha256:b3aa8974f76f845b1eaa8c936b39e03bb66e6cdbc143f207958297a819c84d5b
rhosdt/opentelemetry-operator-bundle@sha256:299ec7215b4f3da785ade49ea8425be2af81689ffc803c3aab248229a5dd2f5a
rhosdt/opentelemetry-rhel8-operator@sha256:9c06e6b90880e97ce6e7b15d218057a0d0440d313550484619cf2ee5329c899a
rhosdt/tempo-gateway-opa-rhel8@sha256:57606d7836efd17347c0ceffbbc3f8b49b0c4af31cbc02fd99a3da2b14d1d396
rhosdt/tempo-gateway-rhel8@sha256:0b391aee88ed6f569737ab84082966715ac26e9bb3d9ca0517578f77fa54e4e9
rhosdt/tempo-operator-bundle@sha256:0ecda5259499a794a9af729a29a1691f7b029c5d287c6705477fbbd3040acc41
rhosdt/tempo-query-rhel8@sha256:e5860305c2f4d8b276b484e3db15fe5f7444649d9d76ce9664dc286f33a8363c
rhosdt/tempo-rhel8@sha256:0baf5285f10484b25ba140b147df587eaaac146e32b2ced643fda52eb6353859
rhosdt/tempo-rhel8-operator@sha256:c3a78e55a18c3cefe2b79ca6d1c0f43ec8bf24573d8575992fa3f188471ef64c

s390x

rhosdt/jaeger-agent-rhel8@sha256:21d8fa0f0a030ce27c9587d647b7e3cbacd83b416ccbebaee10d1d2c9ab9f7d4
rhosdt/jaeger-all-in-one-rhel8@sha256:100cb4237de731039f1689a98eadce7a4ab32610585b88bd39421e5bcbc4ff0f
rhosdt/jaeger-collector-rhel8@sha256:9d79b4fef8b2a58fe840a73a5b5d045373b2aa2ad4b5f986db0bff1e8ca8ac01
rhosdt/jaeger-es-index-cleaner-rhel8@sha256:bc4d0bc9f7d35c6f94df03f095c051994be2d690379e322eff7d9a570257bd5c
rhosdt/jaeger-es-rollover-rhel8@sha256:c17d71124489396b026e507f126fd0e701fbeffe5fcdd3a2cdec8c391d0514ab
rhosdt/jaeger-ingester-rhel8@sha256:f42aba536e71a6168bdfecca1cc5bdf4f41b02eb172a6efbbd63d6cf1053e033
rhosdt/jaeger-operator-bundle@sha256:af0f7adabe6617aa366e69a53756d0855c9f00bd973b0c1d8627845820595d30
rhosdt/jaeger-query-rhel8@sha256:49b45c0ffbd25fa21989966120c9ea162a90f181e01c2138cdc4fb294d180bd8
rhosdt/jaeger-rhel8-operator@sha256:2789597df07b8dd04c3e95938a94d9b0f40e7c048e3fb58e3c4b84eea7e564a7
rhosdt/opentelemetry-collector-rhel8@sha256:fcdb0bd7733c69cf10fc32874dbeb0bb3ff9bd79415ed4bc1416c8e3f2ebc315
rhosdt/opentelemetry-operator-bundle@sha256:122c8f6101ea0288ec045d15e1d19a2d1d61aae3d04c9422128a2f7429e51ff5
rhosdt/opentelemetry-rhel8-operator@sha256:1e863a5424685d0c5a328a49735c6585b2506693f5620ea1616dd5d43e4e2381
rhosdt/tempo-gateway-opa-rhel8@sha256:127b7187d170a63325c08f01936d323008e7ad91e1309dd0db886f2d3ee5e991
rhosdt/tempo-gateway-rhel8@sha256:39fdd72fa31f524455421d7296b34f300755249778e778bcf49b3b1a822faef7
rhosdt/tempo-operator-bundle@sha256:913fdedf596886841dbf0a0fafbbc75330df2a03e966950a7dab5b5cd4caba13
rhosdt/tempo-query-rhel8@sha256:489afafb655f7a7746f5634b1b9a3b83b71e366ed2e145eb59a7d143f9d84f9e
rhosdt/tempo-rhel8@sha256:bc45d1ca3f6f7ef339d1270ff6c4ca392fdbb7d36f5e8b5b76458ff56254d34c
rhosdt/tempo-rhel8-operator@sha256:182ab00f77c2fc7bcf5e7ebdc86b49ec13cc368234dfaac36fee914daecfa538

x86_64

rhosdt/jaeger-agent-rhel8@sha256:6051b1c3f9238bcfb496df7ff68638f8e14483ccac30d33fb0ca590b0f946473
rhosdt/jaeger-all-in-one-rhel8@sha256:ecbbab7413c79b4c17946a5cf5fb75be4a1ae8d3b8cb81f0e4512de14e071d8a
rhosdt/jaeger-collector-rhel8@sha256:a081cf48c42de0dfcaf04d6a5f8eb24f9e638a10ee94e1146c83a95cf0aa78b4
rhosdt/jaeger-es-index-cleaner-rhel8@sha256:ee207170af3cbedc86820c205a84ba07dd8b3a85a365f77642e6a3a8a8bffd01
rhosdt/jaeger-es-rollover-rhel8@sha256:1f32b8c6c75f703698d4e2651940eaf7aa229c98ed8acb0efb9eb268b83f1715
rhosdt/jaeger-ingester-rhel8@sha256:bb9d9b51e657ccf37705a393cd8efd0d6880fbfc2bb484914652a43c39695f9b
rhosdt/jaeger-operator-bundle@sha256:cea64466e14175545417779cfc72e2a7394f911d26b3abc223d8930cb37c8642
rhosdt/jaeger-query-rhel8@sha256:6a898bfa2a63260f9bcd16929d533f14e706bd2383a46f740e789d1d097c0bed
rhosdt/jaeger-rhel8-operator@sha256:3a17fb9b12912384623c73f91813d1b615ce264f28105eafd00c03922cdcf15b
rhosdt/opentelemetry-collector-rhel8@sha256:7c8e08a1a466603304a4543bfb03b86edfb4db8d1633e4a5c51ed706f94f95c6
rhosdt/opentelemetry-operator-bundle@sha256:96f07636b69ff639d3a1f17ffe8b9bde8ed2cc1307b86fa016cd5d716a3c97e2
rhosdt/opentelemetry-rhel8-operator@sha256:3c96566d177d6cff012533b3813bb7c9f03dbc110c52746f32c46bba5fc99d51
rhosdt/tempo-gateway-opa-rhel8@sha256:d1bd74c11a6a3c999344149b3db231acc29ab9b66e6e83f5769b76ec84979d52
rhosdt/tempo-gateway-rhel8@sha256:8b82385bd6ea85049822a7c38d93f6e4418c1d36cb57802751bc13dbe974da18
rhosdt/tempo-operator-bundle@sha256:d3d446b9adaebd3985fb8d78176100156d9133ec2cf956d92e07c3651e60cc3d
rhosdt/tempo-query-rhel8@sha256:0cf7bf3c7f099bd44e71244895c980f9e799ac4705d96b523ba4da0944d1b505
rhosdt/tempo-rhel8@sha256:a8873e09e4806402f8ea42a5a4c10693d4d863d028e13bf1a5c66a76296e2e22
rhosdt/tempo-rhel8-operator@sha256:5274d65e763d6ec540bebc44ac1440586c3e477d403e20a66a8cb95af4c7aedd

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility