Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:0695 - Security Advisory
Issued:
2024-02-07
Updated:
2024-02-07

RHSA-2024:0695 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Logging 5.6.16 - Red Hat OpenShift

Type/Severity

Security Advisory: Moderate

Topic

Logging 5.6.16 - Red Hat OpenShift

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Logging 5.6.16 - Red Hat OpenShift

Security Fix(es):

  • golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 8 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 8 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 8 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 8 s390x

Fixes

  • BZ - 2253330 - CVE-2023-39326 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests
  • LOG-4967 - [release-5.6] Loki doesn't watch the `spec.storage.tls.caName` for updating the status

CVEs

  • CVE-2023-39326

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift-logging/cluster-logging-rhel8-operator@sha256:7a5955b5831371a6e88a3d1eae8445cb69921ea96a23774cb42e700ac57f546b
openshift-logging/elasticsearch-proxy-rhel8@sha256:0870ada19aa90a4d4aa485193d6cb3823fac688488d970acabe489d4b40ad9de
openshift-logging/elasticsearch-rhel8-operator@sha256:c963696c3d048fc9de3968f6bbec2dc47788a9ec44afa53b62db5c9a0148c140
openshift-logging/elasticsearch6-rhel8@sha256:2d6d3ff065acedfaf8f240a0640eec6dfdafcbd90e9d141ca280e913259f87c0
openshift-logging/eventrouter-rhel8@sha256:c4aff891e72e4ff2518d0af6d689fa58a7a493f772d7b9deb19b605930826095
openshift-logging/fluentd-rhel8@sha256:f13e43d2308755734cc811452d0542ef1e516334e8b64d1a208bfe34baed28b6
openshift-logging/kibana6-rhel8@sha256:46bd56f6bcb579aaafbb7d55e176e708204e233c278d6e1b04c82950f8e449da
openshift-logging/log-file-metric-exporter-rhel8@sha256:74e3cacedb6f7e7a32ebff3415b5e9c9ac39b920ab77e8864a0b9f07babaada8
openshift-logging/logging-curator5-rhel8@sha256:9ad846d83819dff7e534b711fb10d465dec6eb3fe2a004d64ea7df3148ef3c26
openshift-logging/logging-loki-rhel8@sha256:e239c98e289d25f4e3da332d31777b06c367f21fcd126999dc8b2af8e984a63a
openshift-logging/logging-view-plugin-rhel8@sha256:8e0406b764036ddca962a3adb41ba060a5da835418e0fb2b77d056bcb2312776
openshift-logging/loki-rhel8-operator@sha256:2c244c57593c6def235b4d56537008c3dc40bdcf69a8ce737169b3ded70b2a87
openshift-logging/lokistack-gateway-rhel8@sha256:72bd8811186893f25f758f19ef34dfef3378279d47ebf539fc3c9b247da6620a
openshift-logging/opa-openshift-rhel8@sha256:a7cd1476e6fcfce939c9aff5cf70cd27243aa78c8e3645bf716a4a74b28865a3
openshift-logging/vector-rhel8@sha256:253bf3c34d055b3099531c9d092cf8aaee67ad7a1c00f0e406b1b58406afd493

ppc64le

openshift-logging/cluster-logging-rhel8-operator@sha256:96ca23328dd2487ddb86f64535ab8a13df61bff2b2c3c53a7b2dd24fa2097802
openshift-logging/elasticsearch-proxy-rhel8@sha256:e7b3655b81bb8e89f3cbf713c652c0ae9824e0518a71379e11a514e461257743
openshift-logging/elasticsearch-rhel8-operator@sha256:b229c04cf6b9ac2967aa78f949e36df6c23c8f01d9cda03f467539944c216559
openshift-logging/elasticsearch6-rhel8@sha256:cf3780141ded99fa44e3aa170ae930ce0c2a7efc6d20e85ddf28943728ef6b40
openshift-logging/eventrouter-rhel8@sha256:542ed6049ce4f6bc7bfe5587d16dccd2f7f1bd7ea049eccc1f8dcb8fb0d8c445
openshift-logging/fluentd-rhel8@sha256:a08a6b780e49a49ccb8c97c147a7415187cf04a7b87063eedb8d457553de602d
openshift-logging/kibana6-rhel8@sha256:8774a857b7496adbd97e63521aeb717714b1c24e4f27f53833333fd25fb3f405
openshift-logging/log-file-metric-exporter-rhel8@sha256:26486a663cca3e38b2dbe822ed63cc78e870bc578319fa05fb20cb8e2244e45d
openshift-logging/logging-curator5-rhel8@sha256:0c0b511229f070cacd5c814a88f1b92588cb6a78d78f2b733c7453daa3a4112b
openshift-logging/logging-loki-rhel8@sha256:f509aac0abd2d7c4a122a6570addf776f51eb28ba88810217199e722106bbe74
openshift-logging/logging-view-plugin-rhel8@sha256:adbe5f973d2fcd40db5e45d3ff548a0c5af47cdb62cc32578b109b05f000847c
openshift-logging/loki-rhel8-operator@sha256:8bd1dd220555c752cb982cbf2c835b1bb28fff8eb6a5d7269ad7de935263f11d
openshift-logging/lokistack-gateway-rhel8@sha256:cfe7bd28a06f708772e80517ab2cb4212fb2d214eda2725a08ced0aa4ae2b045
openshift-logging/opa-openshift-rhel8@sha256:128cb8bf00dfa1c2df0b3112543b84f90c88e3f0306566d5176a4310cd59eaf4
openshift-logging/vector-rhel8@sha256:23173fb7fc947cd81c359579b6d774b206b4625e1bd17fe8a625c0e6e1d26ee1

s390x

openshift-logging/cluster-logging-rhel8-operator@sha256:09d162d94c6ea7d95924b0cdc38c93f227084171259bfda676828ea66ac50fbd
openshift-logging/elasticsearch-proxy-rhel8@sha256:f88432037fe9d93068ef3fb89191c248a2656fd2bd028613b6706a260e1d556e
openshift-logging/elasticsearch-rhel8-operator@sha256:caf95d55e705ffcefa3387822ef0ca0c102e0c4b8c5ac7e7527559822f25a1c8
openshift-logging/elasticsearch6-rhel8@sha256:b703a0a0912b7956dbe02da4b6f31ee372b20f94244ed7b8b8ce260dc3833567
openshift-logging/eventrouter-rhel8@sha256:264b9bf82da7a09cb3ba0c291276b6c86957598fbc838b0fabc677a8d0c2c664
openshift-logging/fluentd-rhel8@sha256:3d65c73a546b7a1eda2222553286590a38621739c87a45c11896a08891ff8e4f
openshift-logging/kibana6-rhel8@sha256:9150f86ff9ff36b88ee8ee89fbc65d985dc7d078fc8b19d190e929e23aa58f45
openshift-logging/log-file-metric-exporter-rhel8@sha256:87334ce27676c430b4765d73b2ff9a4176efdb36ba5721e36fb55ef673a78b3b
openshift-logging/logging-curator5-rhel8@sha256:16299c9f9bd542d62f8e58b17fc808e75dde637491d94f81784d5951904a13a6
openshift-logging/logging-loki-rhel8@sha256:23e4bbf44c40f7884337a92eb85ce9610c7bcb513cef84cb78c8daa1f63a608a
openshift-logging/logging-view-plugin-rhel8@sha256:fd7f325b9f62d892430b7af86ad9d6cda7128f60673cf24d7a23b7bf96d81ebf
openshift-logging/loki-rhel8-operator@sha256:7ae5c06c24323cd59f14e96f9b473619b831146db67e74855b2527ae81f787ea
openshift-logging/lokistack-gateway-rhel8@sha256:5afbdb16d60c422e59948bf581e1ead31f5ae7b7edc67f328b8ca8739d8ba9f9
openshift-logging/opa-openshift-rhel8@sha256:e60f2c2a00cb0ce1b03f6e4c755f1c630d0eadec7754464a5211b1b07d4a61e3
openshift-logging/vector-rhel8@sha256:63452b663c5a2a2e14759c18da22674c7bb991d0b848958d1a2dc51ab9559616

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:edd7c2c4d72c2ffd1905e640eecd67b39dc0e8b4ae8627f08dacc5273172dd80
openshift-logging/cluster-logging-rhel8-operator@sha256:2e60e8ce9a3e8f00e80b550906241e1b9bfe25e028b474e4ee6a311ad0364451
openshift-logging/elasticsearch-operator-bundle@sha256:222dc97a66da5a403062716317a91ac9bf4e614a95e12c224abef077f05ac9ea
openshift-logging/elasticsearch-proxy-rhel8@sha256:507bf73e22962a1f016dc5d3222743a28b302ca62a389e3367dc8b28a9492390
openshift-logging/elasticsearch-rhel8-operator@sha256:9895e52efc12e8c119f0546413bb5d6b2eb3c4f00428df4e3b712d568c463034
openshift-logging/elasticsearch6-rhel8@sha256:0116421b2debc8d42d59e755fdaf0fa7954fbceec5572681b0d7a7ed040a95a7
openshift-logging/eventrouter-rhel8@sha256:c7f4779c7df421415880a8ad13953e309dced0e107e952b27ecbc65fd76de546
openshift-logging/fluentd-rhel8@sha256:e5d6949296a00ffe492757c5f9efeae7f323b7090d9b88da799d588cd3f55259
openshift-logging/kibana6-rhel8@sha256:4939034e2900cbbcc92a46b3045e5dc93ae18672b0a1584e384ee2c2121b6713
openshift-logging/log-file-metric-exporter-rhel8@sha256:d6df8796b7c16a1484047db2381dbe192730799724f7ce82249e6a399b6f4f77
openshift-logging/logging-curator5-rhel8@sha256:cf29687e43d4779e549f7d8d499307b3ba21ccf4cc946155de13b0a177f64d5b
openshift-logging/logging-loki-rhel8@sha256:c960d74ca5a67e7d96161e11b7f02ad03ae9a9d4449885ef30f6589c3119a0db
openshift-logging/logging-view-plugin-rhel8@sha256:4fa453db8b06be7bc7ce0bf40a2cdbfcdc3c4b870caa5bc8453a90baa85be002
openshift-logging/loki-operator-bundle@sha256:8a055214be2cea8ff6a8de75dd97b5d9bc1ffe32db449b911433afdf9bfa69d4
openshift-logging/loki-rhel8-operator@sha256:f408d923479b86c5af2139f0354441f912865a5dd140b17f8c9eebf9c2067ebe
openshift-logging/lokistack-gateway-rhel8@sha256:4fbce7be41454b92475ad7f796060280b557d1c3d9779c4f1eb40ac7c3834e30
openshift-logging/opa-openshift-rhel8@sha256:985c83b235ee6527463c2619ef8e8bedbbb63c68070f242a32e5211a820c8614
openshift-logging/vector-rhel8@sha256:df388c37782dbf0ff523cbdfa2bd51a3bbbb9c93a503500cb329862ccd9376ed

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility