Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:2929 - Security Advisory
Issued:
2024-05-23
Updated:
2024-05-23

RHSA-2024:2929 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: logging for Red Hat OpenShift security update

Type/Severity

Security Advisory: Important

Topic

An update is now available for RHOL-5.6-RHEL-8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

TODO: add package description

Security Fix(es):

  • golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html

For Red Hat OpenShift Logging 5.6, see the following instructions to apply this update:

https://docs.openshift.com/container-platform/4.11/logging/cluster-logging-upgrading.html

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 8 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 8 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 8 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 8 s390x

Fixes

  • BZ - 2268273 - CVE-2023-45288 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
  • LOG-5529 - [release-5.6] Cluster Logging Operator is producing stale telemetry metrics

CVEs

  • CVE-2023-45288
  • CVE-2023-52425
  • CVE-2024-2961
  • CVE-2024-21011
  • CVE-2024-21012
  • CVE-2024-21068
  • CVE-2024-21085
  • CVE-2024-21094
  • CVE-2024-28834

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-logging/cluster-logging-rhel8-operator@sha256:c0ab5ca070538ba1c929ae859394d469365d880ada0406c58aba47cd570b166b
openshift-logging/elasticsearch-proxy-rhel8@sha256:00ffe6bcfecf07a92b3b22c1f4ae4bd081f58d60bd287e30bfbaff9db4e08e2d
openshift-logging/elasticsearch-rhel8-operator@sha256:f61bed36d93956fd0b3df02c59a6c1d33dab7ec1334bd87d5b269d2abca3b326
openshift-logging/elasticsearch6-rhel8@sha256:21861eedf299ea5f07d11d99f9b99802c10ea6a3931af7eba877ba1785d8974f
openshift-logging/eventrouter-rhel8@sha256:86c2b052511d23f1dcff7c4c1b5d72248f5636faa3baf621f6b39eae658c6bd0
openshift-logging/fluentd-rhel8@sha256:a6cc4bec652f78b4e4af1a3f3a4d598037ff160525d44f8c365b296d5dcca163
openshift-logging/kibana6-rhel8@sha256:2bee7d13eca0139913259bf33107eb595fd8c8e6e2cb4f1b279c9679c62689bf
openshift-logging/log-file-metric-exporter-rhel8@sha256:c32bca1304d02c125fb7cc0442e6582cdd0e2bbf86a2c74c166265ea186508a8
openshift-logging/logging-curator5-rhel8@sha256:22822ecca302baaff118b6f10e55044d0cf5140ceace7881f6985da1f407898c
openshift-logging/logging-loki-rhel8@sha256:7829acc341ae10b835888a680c203b1057347527f46f101cc0c1cca3617c57c7
openshift-logging/logging-view-plugin-rhel8@sha256:8d15598e7c617bac67d0027749c3d1fa930e5b0c328c2595db45e236296376ba
openshift-logging/loki-rhel8-operator@sha256:4417fd2330dfd900f650ecd3521a6e0bee06ae0ac76cb9d7016608bd9fb9ff23
openshift-logging/lokistack-gateway-rhel8@sha256:8ce58b5d08047ef3ea19c2a05dc19d818dd86d05f100b34f23eac2a25c9f2572
openshift-logging/opa-openshift-rhel8@sha256:a0d73b892a19d6ece140fe2469b7c02d92a49d6dbabcbe22deae602a60c34ff8
openshift-logging/vector-rhel8@sha256:b9de3ad2251161e7e127d39527c93a684b7e8b1e4e39ed987270628180eac113

ppc64le

openshift-logging/cluster-logging-rhel8-operator@sha256:187ac933f9ec7661a44a7170f57af98e3f603cff7104ec1aa4f9d64ca38f4565
openshift-logging/elasticsearch-proxy-rhel8@sha256:71e60f43eab5c3fca8122a52147454cdeea5ba09e4c5b93266e5c3732f377126
openshift-logging/elasticsearch-rhel8-operator@sha256:ff38f506b00322fcd78007ce2513f0c3600d4d4169764c871f43969e034d3c69
openshift-logging/elasticsearch6-rhel8@sha256:b2d4561100b8cd912b6b2a2b3a3ca377292dccddfa7b062c23af0eef8299b99b
openshift-logging/eventrouter-rhel8@sha256:fe28b07cef0691d423ad05f9142300203c685bc641530f786173a81593824926
openshift-logging/fluentd-rhel8@sha256:b530551aa7b4c0ea3d52ea7dbb396ab333ca955e26366d72d0c7f807cecf697d
openshift-logging/kibana6-rhel8@sha256:1439553e1abf56115e66b3a1184ccde547bf7b7a94e908db77efabbd310bdb5d
openshift-logging/log-file-metric-exporter-rhel8@sha256:66cd147e89ba7287512118d4a7fa001d3d1bb5817ba86977cb732fab449de53f
openshift-logging/logging-curator5-rhel8@sha256:7098187caace8bbc42fdbbbf4ec34872a0a3d113e82e808b4a0d74103bc76439
openshift-logging/logging-loki-rhel8@sha256:371692f70ccc31947a29a32d17a865e142c17dbc89b0fb83cc54beb488fa566a
openshift-logging/logging-view-plugin-rhel8@sha256:e50274625e0bf0e1eafb2053604951460842d416a71ea1185a457a98acaa9457
openshift-logging/loki-rhel8-operator@sha256:9cde0eade0281c238cf8d9741f482ab65ef2e73394369f7bd5e9247989698ede
openshift-logging/lokistack-gateway-rhel8@sha256:34a2ce3aec49a14f2311223d65ea002606384c3336e2403c8234d4ff1196e9e1
openshift-logging/opa-openshift-rhel8@sha256:376d2b1d7202a3fd04669ec138917a3fe37590a36bc78dcf3398fd997d6d610a
openshift-logging/vector-rhel8@sha256:91476c44682f82e16db0960fab216f5d1e506f4f9e1b71c32160e81eaf222002

s390x

openshift-logging/cluster-logging-rhel8-operator@sha256:26a2c965d80a687efe8abf20098574eced63d33b113426bbf02676a91cdaec81
openshift-logging/elasticsearch-proxy-rhel8@sha256:35e0f2f958eca2c6c65a400311aaedc892c50b308e19b444b81a5c34152cee1e
openshift-logging/elasticsearch-rhel8-operator@sha256:3284a445ea1ee777dd791ce9ade976d0979bebc7d2ef1b8ee12d7e2a8975beb6
openshift-logging/elasticsearch6-rhel8@sha256:ac0d3928b83b4cfcbd49f1ea3f2347be12bf36ac7a7da23bde1104a53191ef8e
openshift-logging/eventrouter-rhel8@sha256:7a4366860941e811490e2e6a649dd313ead6ca69d0b08861f939f757d6504fae
openshift-logging/fluentd-rhel8@sha256:52c9edc1fbcf08202c53ef031afa5cfaf84a921d9400f2b0cd6a52ff95be4258
openshift-logging/kibana6-rhel8@sha256:f3e507281e863f20d31a12c743b01b9764a3d33d629783067840f906d72b1103
openshift-logging/log-file-metric-exporter-rhel8@sha256:0d4b324a4726c9a495c8f3f6334b101a8630d5643e2a24ecf1f9976beeb987aa
openshift-logging/logging-curator5-rhel8@sha256:c75535b311bcbee9253369cb0f86277af3d7e929913b1cf53536bfec5d6b771d
openshift-logging/logging-loki-rhel8@sha256:ba73a21803df6f0516658bd30dd24e9ec4a948ccb955d36cb38365bbc112e4bc
openshift-logging/logging-view-plugin-rhel8@sha256:492a612f8d74cd4843e540e6778d256ab7a696bca923989c7241f20f18e68327
openshift-logging/loki-rhel8-operator@sha256:ec15e5b8266d016bc5843d3df51c8c539153dccd4225a369ee203e16e47cc276
openshift-logging/lokistack-gateway-rhel8@sha256:78813f44da05bcd9326f038b868aa8545e96a58a5d7a53a5cf9852ce410ef981
openshift-logging/opa-openshift-rhel8@sha256:b587aa9eaf4f41f61bd010d1def0f5254379a93f71705e9d46269f4dfa3375fd
openshift-logging/vector-rhel8@sha256:cf252ac88ea891642e1dd6377fa7e312a5a652c4bdf8829700b18fd8b1ef37c5

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:1ac77ae26db0a0a62541ea3997d43d06b6b77cba6b3cbb62630723d731c088c1
openshift-logging/cluster-logging-rhel8-operator@sha256:771510bc988b79286869d5f501e7361191c0199650dd2875a967580b526db3aa
openshift-logging/elasticsearch-operator-bundle@sha256:d1882ce4aceb2915b624f244b43fcf27f310a6627b255e7a39d76cd8bcb4fbbb
openshift-logging/elasticsearch-proxy-rhel8@sha256:16d87d17f2ccf3037a159c4a1edf6d0e0b9af5adc8da9b4f2081f5b34c8d8928
openshift-logging/elasticsearch-rhel8-operator@sha256:34b8995031ebf6931fc37bdb64e4ce4216d1d2a3acb810c8541c6d9b65eb0b12
openshift-logging/elasticsearch6-rhel8@sha256:627aba20bdc63c6bd13283f8344287b0a92368278420979ad751afb20863c073
openshift-logging/eventrouter-rhel8@sha256:5c2bdd7799a419af2f06c6ade1ee9ea60294c7cad77d9163de893217b64dc1a5
openshift-logging/fluentd-rhel8@sha256:21654d3ae2805214b7972948bd18eb13fcdedbe7d0e7700c31e4e70df8e8fb18
openshift-logging/kibana6-rhel8@sha256:e1d5ccd9faf1b9c39d686973387d690b91d3ca8177011b7886192ec273311057
openshift-logging/log-file-metric-exporter-rhel8@sha256:d34eef63fa54e8de1d9d5bbf94ce8e876909337b1430537090c48dc4c6196d58
openshift-logging/logging-curator5-rhel8@sha256:f8021819435b40b8187238ecbddfbfa4b9d9e06269e1b52362dec424dcd5cea1
openshift-logging/logging-loki-rhel8@sha256:a242ba080079d36da742db65dc80a72d0209a4c403c05bd35fdb3fae830a5f32
openshift-logging/logging-view-plugin-rhel8@sha256:741c99f5624d8928ce46acab54dde7eb61451813fbed26bd5509bb1e66b22091
openshift-logging/loki-operator-bundle@sha256:dfeb444503ad0b421cd951f9f66eba001e3b1ac8a01060c2cb5c04be5c5e0290
openshift-logging/loki-rhel8-operator@sha256:e7867bb0ccdb9a4010d54b0c70530ac6c0419f59e6d259ad58c8d2399a366488
openshift-logging/lokistack-gateway-rhel8@sha256:a1bdf15d3ee379f7addd6bc8edd1f77fa8cf55f6a64034331ab8f901026c8a8f
openshift-logging/opa-openshift-rhel8@sha256:e7ae951caf6df4cbf86c22efab1114e18ea4fca6c44a6f2b98f209688eb3c85e
openshift-logging/vector-rhel8@sha256:01b00bac7593528af137f5d8903d0a9e2aeeab9aec851d3e9894c2eedc1427d6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility