Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0271 - Security Advisory
Issued:
2024-01-17
Updated:
2024-01-17

RHSA-2024:0271 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Logging Subsystem 5.8.2 - Red Hat OpenShift security update

Type/Severity

Security Advisory: Moderate

Topic

Moderate: Logging Subsystem 5.8.2 - Red Hat OpenShift security update

Red Hat Product Security has rated this update as having a security impact of moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Logging Subsystem 5.8.2 - Red Hat OpenShift

Security Fix(es):

  • CVE-2023-26159 follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse()

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 9 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 9 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 9 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 9 s390x

Fixes

  • BZ - 2256413 - CVE-2023-26159 follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse()
  • LOG-4890 - [release-5.8] lokistack ruler Error while dialing IPv6
  • LOG-4947 - [release-5.8] The regular user can not display app logs after grant cluster-logging-application-view role on OCP 4.15 Console
  • LOG-4912 - Unability to configure nodeSelector and toleration for logging-view-plugin
  • LOG-4951 - [release-5.8] Operator - Ruler unable to send alerts to UWM Alertmanager

CVEs

  • CVE-2022-44638
  • CVE-2023-1192
  • CVE-2023-5345
  • CVE-2023-20569
  • CVE-2023-26159
  • CVE-2023-39615
  • CVE-2023-45871

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift-logging/cluster-logging-rhel9-operator@sha256:badc0805402447cff783c5bc7fdc7dcde6ac84c03f69f054be895974bb2c9613
openshift-logging/elasticsearch-proxy-rhel9@sha256:d2f6c4ca49c88013e393ef0a002a920a413d15d185bb37eccc790cbe8ed0ce1a
openshift-logging/elasticsearch-rhel9-operator@sha256:6610a81367c9756c7594776df704eec06f850a7fa6d71e2e7d0f5d0d264f8ae4
openshift-logging/elasticsearch6-rhel9@sha256:62509d6ae8371aaa99c24b3523d60ca2d7e3a673936cbd30db417ae309c5f62f
openshift-logging/eventrouter-rhel9@sha256:fb6761d386c05adda84a7c2f36a6fdad9109cd4c04e9ba83f6819111928358b7
openshift-logging/fluentd-rhel9@sha256:828502972e9257402ed0fbf79f95253d2095217048b41f82cc0945f8aca14b4d
openshift-logging/log-file-metric-exporter-rhel9@sha256:082467ef380546b4c735b500d4e1a265ab22fff833a4f3b2487aa5deca2c1fff
openshift-logging/logging-curator5-rhel9@sha256:197586b9b180c40aa764acffb1b973cdc466fac20e51757b6ada22e895245f8f
openshift-logging/logging-loki-rhel9@sha256:1912a174442d6dc57076f40da6a55f4c9ed99af5d9dc69d4012197c43a84f7f5
openshift-logging/logging-view-plugin-rhel9@sha256:132e8b5c86cdc6a8ab1732554560358e843b0ee33757b075ccb7009b552aa163
openshift-logging/loki-rhel9-operator@sha256:63a5a10f98a8e4b624bfdfba7a22ca4ddc06e484c0489f43984a4940c872a7f6
openshift-logging/lokistack-gateway-rhel9@sha256:a7a4ac91d26950ca4fa6af8df6b3e54da3c0c07e4fef123ff7119a808457242d
openshift-logging/opa-openshift-rhel9@sha256:ecae432e34e21914a887518aac74ca6f99f574e590b0b0b44e26a3886359ec5d
openshift-logging/vector-rhel9@sha256:f68deb3d8ec1e158a98876d067b9795da5ac6c73b07c190355463f210d84f777

ppc64le

openshift-logging/cluster-logging-rhel9-operator@sha256:573414f16018fc9684ccc2161dca6a203dcd6381c7f1b60da3edfebbf4f528ec
openshift-logging/elasticsearch-proxy-rhel9@sha256:17cc6d8e06ef8155a96a952af57da913c2c31bf275e7c2d5abf01cfc19498362
openshift-logging/elasticsearch-rhel9-operator@sha256:bbf5559a1f54476343588d51b70051d53a528964d4a903ebb3b1059717f4047b
openshift-logging/elasticsearch6-rhel9@sha256:71145fd4f438c500b62e2306adc582c82e333bffb3aeb2fe3e21aa318f9bce65
openshift-logging/eventrouter-rhel9@sha256:4c2c1252931f1f66ef557d8d902fba21870df60b9488f02f4636b61e9f0e7d39
openshift-logging/fluentd-rhel9@sha256:ad119fe91725368b39241baf8dc0519656a3359c1d0bf75793338793a4fc7110
openshift-logging/log-file-metric-exporter-rhel9@sha256:f4d85801afb9152dc18e19742c8c5fb9377029ebb27b34134babaa689898e63d
openshift-logging/logging-curator5-rhel9@sha256:b3546a6b93a37a1b3948ed8e056a4ee478b8fa48ad2c4ed32228ff99bcd9d546
openshift-logging/logging-loki-rhel9@sha256:c2957d159bb85abbb60ffbb6e821d379f83274564c50deb161a370ba799f594e
openshift-logging/logging-view-plugin-rhel9@sha256:9a2817329c491d7031237c59dac70d336a9011690645df0131072ceb916b0424
openshift-logging/loki-rhel9-operator@sha256:11c0baa55347b78e48c6c78abe3723f9081e4b344624fe97011ecb4da67c96c9
openshift-logging/lokistack-gateway-rhel9@sha256:e4f68d74456f57ab2e0b9990b253b960e129215d02dcaa0056c9f792dce8f47c
openshift-logging/opa-openshift-rhel9@sha256:af6b7248f3e74c338105754d123c1210b3e34f7cfa26cd59d584c97d2082fdfb
openshift-logging/vector-rhel9@sha256:a74545c3b0016693c3f9059a509f4d21b55276909c267bbc4860a1106f9b4c3d

s390x

openshift-logging/cluster-logging-rhel9-operator@sha256:e277f27c240fe34f6726d87b0d3f5ddb8c8de66a3152bd5ae9ef9719541286b8
openshift-logging/elasticsearch-proxy-rhel9@sha256:2337dfee28bb2891ca27f58813048b34b71934a1d2555c876f3a85dd011424e1
openshift-logging/elasticsearch-rhel9-operator@sha256:a74e0d9f9cb0e8832871cd46683dd016836895666ea1e5641dde03dfc5a6d366
openshift-logging/elasticsearch6-rhel9@sha256:658508a5825b8ff0cb204f8feb861531c946e380eb7a6f7781b9e3b5c5876852
openshift-logging/eventrouter-rhel9@sha256:024a125201fd92817bc91a5987ccd970cf6600dfee59e25a0eebb4fb4fb70df2
openshift-logging/fluentd-rhel9@sha256:d8d17ee6707e7db6094677216ef861f8fe4d5a48416a4752b34c66a24466a439
openshift-logging/log-file-metric-exporter-rhel9@sha256:3c735e435e2ab415f60400db48bc4e516129da8ba37f6026427b1ef3243b99aa
openshift-logging/logging-curator5-rhel9@sha256:384aec2cce682d08b4840e1efa2d85f4e79fe062e7a47ea8a8338833afb63628
openshift-logging/logging-loki-rhel9@sha256:8aa76307bd75f8619cc62eded6b3f746a72fa20e6e770b1d1f7bac026b217a7a
openshift-logging/logging-view-plugin-rhel9@sha256:f0583ebd88535e3c3a42b9d2e51bb5daa4bfc02a2ecdfa2047ed507276714d24
openshift-logging/loki-rhel9-operator@sha256:add922b643586220b273ea336a7c527edd620b01a38322e6a1139097014f09f5
openshift-logging/lokistack-gateway-rhel9@sha256:6ca1c5cba53d81bd2deb524e137fab40230b88b134d75077e13e8464ab5d5a35
openshift-logging/opa-openshift-rhel9@sha256:acf20ad7502728e06d2c1b8c6045ab06a70ddd98dbeeb61da67bafc5034b0ccb
openshift-logging/vector-rhel9@sha256:947dea497577b7e7420e95f817a28a2aa45e7e02ce878e98bcd58e4f5cd8d415

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:35cbfc34cecd420b840b4742c11c92351b2bfb44e66993fe7337c8b870114442
openshift-logging/cluster-logging-rhel9-operator@sha256:056cfd2fabb5c1cbfc37e57d8b95cac70e54eee8a24d58208dd70395de73bb64
openshift-logging/elasticsearch-operator-bundle@sha256:fb2fa450b07eea2ee577412a745af6a27bee53930fedda9bdf233577f3ea5833
openshift-logging/elasticsearch-proxy-rhel9@sha256:6920abf4fb10f3da7247ed7cbd5bec7f6165cd04bdacf1a359a3a2abc65be543
openshift-logging/elasticsearch-rhel9-operator@sha256:9168f2c9a554251544847cdbc5011f9ae74e27aa1c176803327876ecfe88b73d
openshift-logging/elasticsearch6-rhel9@sha256:f165d220d2d3fab8b13187906afd2094bc0c32e9c8f108bb69c1fa55f936ee0f
openshift-logging/eventrouter-rhel9@sha256:b17ce59f2e1955823d9c6053ef8668dd7bb7946db35c0b132532dd4eda1b68f6
openshift-logging/fluentd-rhel9@sha256:0990c3e6fb25499787cda779832ec626f95792f12288fbbf94802004084cf6b8
openshift-logging/log-file-metric-exporter-rhel9@sha256:b4c532770de8d3fdf51cbc155c28ede3a33c08fc323f68db90301e76ac48ddf6
openshift-logging/logging-curator5-rhel9@sha256:a79195d8555bdb337039076da493afa5759d4cae0ff8a71d17f06e2a181157bf
openshift-logging/logging-loki-rhel9@sha256:762c5b6ab9bd4f9c503bca18546552ab35ae4f2006f61b85ead8ad9c7f16f5b7
openshift-logging/logging-view-plugin-rhel9@sha256:5cb34203ed294f6723d7d1777049f682a5887985299ad974d002005ed41946a9
openshift-logging/loki-operator-bundle@sha256:1cd06b7b8a36ae2763c5be0387b12670cb95b6ec2c4f3c4d88e113ee961c57d9
openshift-logging/loki-rhel9-operator@sha256:8bc04af205c5272de9d58c22eaa3bc7824994718494481ce15343f0a0b8266c5
openshift-logging/lokistack-gateway-rhel9@sha256:1a4fe47116d1fda55a32739db1166b71a726f55481c309a007f0f832a65d0daa
openshift-logging/opa-openshift-rhel9@sha256:7cdd7101fec2b5f6b8dcdb01ad48ed75c4ea863023fddf2b99bdfaf1b102cad6
openshift-logging/vector-rhel9@sha256:48476d55920f42b3e23328f1a1c7061f1f012422c9fd76ce134d730c266e602c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility