Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:7681 - Security Advisory
Issued:
2023-12-12
Updated:
2023-12-12

RHSA-2023:7681 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.14.6 security and extras update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.14.6 is now available with updates to packages and images that fix several bugs.

This release includes a security update for Red Hat OpenShift Container Platform 4.14.

Red Hat Product Security has rated this update as having a security impact of [impact]. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.14.6. See the following advisory for the container images for this release:

https://access.redhat.com/errata/RHSA-2023:7682

Security Fix(es):

  • word-wrap: ReDoS (CVE-2023-26115)
  • opentelemetry: DoS vulnerability in otelhttp (CVE-2023-45142)
  • opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound

cardinality metrics (CVE-2023-47108)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

Affected Products

  • Red Hat OpenShift Container Platform 4.14 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.14 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.14 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.14 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 8 aarch64

Fixes

  • BZ - 2216827 - CVE-2023-26115 word-wrap: ReDoS
  • BZ - 2245180 - CVE-2023-45142 opentelemetry: DoS vulnerability in otelhttp
  • BZ - 2251198 - CVE-2023-47108 opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics
  • OCPBUGS-24302 - GNSS status metrics is not showing correct state in cloud event proxy

CVEs

  • CVE-2023-26115
  • CVE-2023-45142
  • CVE-2023-47108

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/cloud-event-proxy-rhel8@sha256:5adefe64dd438bbef12cfec97582c762ab6d70063cea328349a19b91eee94a6c
openshift4/ose-cloud-event-proxy-rhel8@sha256:5adefe64dd438bbef12cfec97582c762ab6d70063cea328349a19b91eee94a6c
openshift4/frr-rhel9@sha256:0c554f40009dfcf82ca7a76e02b3d31734bfe80a58969e399e245f51766e0682
openshift4/kubernetes-nmstate-rhel9-operator@sha256:754fc25ea38236e982c00f3b7863cd5be5d37ee20cb458ee56da3d99ce255082
openshift4/metallb-rhel9-operator@sha256:e2d4a2104b0b236e218641af2a433c89421f000109003717df9df25a794f8912
openshift4/nmstate-console-plugin-rhel8@sha256:53fe5f4ee11ec1626e7b56567ed175bf4a131b3aa9531029c5899371731f93f4
openshift4/ose-cluster-nfd-operator@sha256:21c88ebddda5d48811ae77054a1b67d319879a820a02188d5788efe2702c34ff
openshift4/ose-clusterresourceoverride-rhel8@sha256:f95025c890f3ff4a1a81699bf6e67ff81c052abbe1d3d172a373cb23dae3a6f4
openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:2587c9f8bbe953c056008b3f88dc2e0acb7c30bf23efa61e091583e922a25fdc
openshift4/ose-node-feature-discovery@sha256:5c4de1d9e4fd455667b3956afc4f596815e9d0184f03c2458a9204cbcddedc96
openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:770a96a13fa974d6af49ca424ec9638b8bc27da310683c6706942962ab3e1112
openshift4/ose-ptp-operator@sha256:8e6f68291b5a9c16cc5961d1e3c0a7e269a11e2c27514c19b6e595b024a2f1d6
openshift4/ose-ptp-rhel9@sha256:eceb6a6bae7ee66f5f71e96589267ae57246671219c1b6b83eccd55294833853

ppc64le

openshift4/cloud-event-proxy-rhel8@sha256:c50f0d3fdff38b8ce78967b276689cc32e4efe749ca19af9f17eb0dde672affc
openshift4/ose-cloud-event-proxy-rhel8@sha256:c50f0d3fdff38b8ce78967b276689cc32e4efe749ca19af9f17eb0dde672affc
openshift4/frr-rhel9@sha256:a4439d9d24b28bbcb842bd676838ae1369a139c2c3d38d39abd954b5acd4a399
openshift4/kubernetes-nmstate-rhel9-operator@sha256:6a031d824d915eff514b8f3b4ef6932c6f113a88e1a07ba24b3c0a04ef547fb8
openshift4/metallb-rhel9-operator@sha256:0e431261b489ebcf47d04fb1f78130ff1e651d41dd2b5cca65fd26bcbb141214
openshift4/nmstate-console-plugin-rhel8@sha256:25c4ce30e6a2d69a3e7f10ad7c5801921bd2e1ca5af84d2472709e4b455a27e4
openshift4/ose-cluster-nfd-operator@sha256:fdbe21487e0681691918408abc18d4239e66c047ff27df2c24e517681f074ee5
openshift4/ose-clusterresourceoverride-rhel8@sha256:655d252844dc20b6f3d651b01d2d7f734058a3cffb4a4055e1e9e0db9ef8fbe2
openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:8a20e5d567f64746b2ecc657f2b9cdb5daf6a5ae69ab10c6bee9cbabc3d4f458
openshift4/ose-node-feature-discovery@sha256:59d416d8d868a17a2489a4c5b9b38b70cf321b0ff21614bd500c29b55720d2fc
openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:5127a266c5add99a099cfc8f71381285b5307a0a56edfd54c3178317fa6fc895
openshift4/ose-ptp-operator@sha256:7100b273c53f9e48b7700bedadd59d3cd2125a6923d57aa229ab4844f1e9e199
openshift4/ose-ptp-rhel9@sha256:8a1cbf9bc27fecd5dd85fa7b2f86b7066161982f00f645f8c1af0d2b3e424fde

s390x

openshift4/frr-rhel9@sha256:b95920113883696201acba9754a932180c3194a7f36c36e04d813f0e16ea5cd9
openshift4/kubernetes-nmstate-rhel9-operator@sha256:9921943d6354f014e6c9d723b479d384da8827708fed076fe33924ab7b73125c
openshift4/metallb-rhel9-operator@sha256:ab597e53d672a44d4ad4356e39691e1ae87523a4fccb82058a9031f4c8f4fe4f
openshift4/nmstate-console-plugin-rhel8@sha256:30e5d88e1ee44159c9fee0effefe84371bf7250bfde4f9886a9c090eb7559b17
openshift4/ose-cluster-nfd-operator@sha256:0d93316577e6d89762574236c54e7f0da33c6b0414a91a92074ad1cd02e575ee
openshift4/ose-clusterresourceoverride-rhel8@sha256:b0dd87c42c053869c9594270389708bbb8c14d57f55a69746956b3659e91c6f7
openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:c654c0073934f51b589ee169d1a377e494a5091e46ece92cc1ac7d7083c54267
openshift4/ose-node-feature-discovery@sha256:d6fd67cd2d16ecfe5e8181f404e5029a2cce0759b19679a0fe4897cca665ca7d
openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:28beffa35d0ec4ba65fe811a307f9c6797636ed091acd3071f9d9d150f9399a5

x86_64

openshift4/cloud-event-proxy-rhel8@sha256:6c99194985bbea419b05ac7d849489bb43ce9c05007c529b0847812c90251982
openshift4/ose-cloud-event-proxy-rhel8@sha256:6c99194985bbea419b05ac7d849489bb43ce9c05007c529b0847812c90251982
openshift4/frr-rhel9@sha256:653dca964b5bcf44a7a7fc2c585040e7de58e8f3bbbd6060524996571e299607
openshift4/kubernetes-nmstate-rhel9-operator@sha256:e6ce9a41e3459eb63d1cba772464f156f8310193c37da6e0f20b0be7f2bd1f3b
openshift4/metallb-rhel9-operator@sha256:07cecb266b131d35b03e13aac718f80cca805d721bfccb89239d32a30ee60d5f
openshift4/nmstate-console-plugin-rhel8@sha256:82f4ada56771dfb7b6b65081d0745404ad464c7c223cd42ea392d040eeef14b2
openshift4/ose-cluster-nfd-operator@sha256:6b3ea013f1f37dd5a4740a69d97e71d20acea6ece1b314f32acf2615acaf6d45
openshift4/ose-clusterresourceoverride-rhel8@sha256:bacf65cded1c0d6dcc713bb41e8cdfecdc3f73b92b06425bfe9bb1ce59a7f3bb
openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:52e96810d73616e716d4fa4eb7de3d89c7665d728412da02b2904eaab9fcb898
openshift4/ose-node-feature-discovery@sha256:bdacf65ea208cbbae70ab1df7eb3f53e8863771dabd959f278fa31e8594d201c
openshift4/ose-openshift-proxy-pull-test-rhel8@sha256:e63d1a392d65452cbd35773c037905616d66aeb2e22afe1950ce777bb35f6817
openshift4/ose-ptp-operator@sha256:eb75e8e5b0a5d6140d73809bc3e6096fd367bcf00fbfb11dc450f94606aa681a
openshift4/ose-ptp-rhel9@sha256:333bc40f33486d63f2e1e66059f74ec0669fb9038a28da2842927aa2c20374a1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility