Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:2930 - Security Advisory
Issued:
2024-05-23
Updated:
2024-05-23

RHSA-2024:2930 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: logging for Red Hat OpenShift security update

Type/Severity

Security Advisory: Important

Topic

An update is now available for RHOL-5.7-RHEL-8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

TODO: add package description

Security Fix(es):

  • golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html

For Red Hat OpenShift Logging 5.7, see the following instructions to apply this update:

https://docs.openshift.com/container-platform/4.12/logging/cluster-logging-upgrading.html

Affected Products

  • Logging Subsystem for Red Hat OpenShift for ARM 64 5 for RHEL 8 aarch64
  • Logging Subsystem for Red Hat OpenShift 5 for RHEL 8 x86_64
  • Logging Subsystem for Red Hat OpenShift for IBM Power, little endian 5 for RHEL 8 ppc64le
  • Logging Subsystem for Red Hat OpenShift for IBM Z and LinuxONE 5 for RHEL 8 s390x

Fixes

  • BZ - 2268273 - CVE-2023-45288 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
  • LOG-5472 - [release-5.7] Cluster Logging Operator is producing stale telemetry metrics

CVEs

  • CVE-2023-45288
  • CVE-2023-52425
  • CVE-2024-2961
  • CVE-2024-21011
  • CVE-2024-21012
  • CVE-2024-21068
  • CVE-2024-21085
  • CVE-2024-21094
  • CVE-2024-28834

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-logging/cluster-logging-rhel8-operator@sha256:ed41b5450aa91a1dbb519acd184f87f96e090be3d099e88dc27a005bdc9bab15
openshift-logging/elasticsearch-proxy-rhel8@sha256:6934dffdc619dad6e81ae2032708d41e487b2709c14794819accdaa60aae582e
openshift-logging/elasticsearch-rhel8-operator@sha256:3be80c8c50ed785eba9d289656cc87477b5a3a1bdd71fd91d048c66687ce4646
openshift-logging/elasticsearch6-rhel8@sha256:3b42c3d5afc01b5e025f4694454c34c4577e7902d2004620e1d97940b9fa13ab
openshift-logging/eventrouter-rhel8@sha256:20eb0257f8ca0dce4e5d979a579b2d868c7b5313a661b2ab9dfb3c6f97bd0d69
openshift-logging/fluentd-rhel8@sha256:4dbb10ac48ebedcd08e4d93d7958876d7c489b3c0764a703979c4cc16b2faef5
openshift-logging/kibana6-rhel8@sha256:c92d7b58be4a5dd715101723b187cf930e7b86ffa6e7a7b3119b7512c0f68639
openshift-logging/log-file-metric-exporter-rhel8@sha256:1ddec93f26b66624a8ffc6d6af6141f71df2bd0661f3038d327c787d1b61edd1
openshift-logging/logging-curator5-rhel8@sha256:75e342825c86def4e8bd85f19377e2f79931acfa5420fe1bb7af64011560db3d
openshift-logging/logging-loki-rhel8@sha256:f5f7a3f069eb73b92aeaff8b8a6ad55459eb526928491abb0589b28017fbe705
openshift-logging/logging-view-plugin-rhel8@sha256:1493fa1da9844aec3b3cb7506d40cc457aeef5204b5441cae47dbdb6a9ab249b
openshift-logging/loki-rhel8-operator@sha256:48af23673bf8432a192fed8ab9cb9f4a633ef8f26293253c268bc46360bb835e
openshift-logging/lokistack-gateway-rhel8@sha256:96e662c9dd20c2f94edcd83660b3e99ab0e0134a641d25ab3a391581f52055af
openshift-logging/opa-openshift-rhel8@sha256:e8e0d825d5c55f09547af8d267486a3c33cdfb5c4733b8f85eac817cf9bf93e5
openshift-logging/vector-rhel8@sha256:f635cf3c647aeb72a6af00d97b4966dae041fe8d42722bded29c0de31181a7f0

ppc64le

openshift-logging/cluster-logging-rhel8-operator@sha256:bcf26dae2241ded8335e3236944639643ce63027a24645d2de0d013589e79876
openshift-logging/elasticsearch-proxy-rhel8@sha256:6433a808ccc5c4c1559c183a81671b7249c3bae1bbc0f55e982ee73dbe9700e3
openshift-logging/elasticsearch-rhel8-operator@sha256:e902f46cbcf188bc6e50b2351cc20465a7a238e1521568261a50f8cd33108752
openshift-logging/elasticsearch6-rhel8@sha256:e2839a1a45aba4a367003abc7bc4e15531d6f278de1779f4c063ab6a002e960a
openshift-logging/eventrouter-rhel8@sha256:492d612cc28ad4158d2fb071704ada6d667d939000ff4af20ab9ed3dc1c4a53d
openshift-logging/fluentd-rhel8@sha256:95cd644aef3ed635fab4a04e8dd9e63a79812e2671a706dcecfcfb462fa9f287
openshift-logging/kibana6-rhel8@sha256:ec811d44ffc9fb926808773bdb33789411c07d46809c7318bdb9568575204fc7
openshift-logging/log-file-metric-exporter-rhel8@sha256:dbeff8644fe3cfe045e9658eae6d697fe2ddb979ccf06952fc955ebe1aa0aa3e
openshift-logging/logging-curator5-rhel8@sha256:7ff67be12dd4c12b90788655f8269216d60d2008481e34e5213798d99b73f085
openshift-logging/logging-loki-rhel8@sha256:909e4ffde6fe17c9449e8838805ec37e749a7a3bc1794e76df5a1214264f662f
openshift-logging/logging-view-plugin-rhel8@sha256:c4eb628e9e1b3ee30676098151cb7a4f9b05c25e464555899becf6361c04ab97
openshift-logging/loki-rhel8-operator@sha256:f2e57a021477b3884aa2ba88b3052ba8b14a50898659faaee1b31259b6461767
openshift-logging/lokistack-gateway-rhel8@sha256:851f91c9b8fb0fc5c73c1357d41f79f8b98d0e27b440259de6c951e77ca6227a
openshift-logging/opa-openshift-rhel8@sha256:969593b2998dd62e5a823d20632225e0251814077687578370603795c6861fc2
openshift-logging/vector-rhel8@sha256:cc9253be2cdbceaf8ec120aabc9f4fdd603f3b9ec190c24fd05e95f2863b5ea9

s390x

openshift-logging/cluster-logging-rhel8-operator@sha256:a1aafbebeca86cf4b52600bca4c3014881c1ffca7587d2d382275a3d247d72e9
openshift-logging/elasticsearch-proxy-rhel8@sha256:19a6691d7a3010253bf18a00a1b58896350354494375822744d08a09e0121416
openshift-logging/elasticsearch-rhel8-operator@sha256:6f6b013bef1ddc9ec0437c0c7727bb0f8ebf9caae8ba4cf0dd6628d6c7cd768f
openshift-logging/elasticsearch6-rhel8@sha256:1c6c3634aae0f7a47fba4f1a06530e742a0042896291579642a605b53105c019
openshift-logging/eventrouter-rhel8@sha256:1194cc3737cb2317e3f4b9760d2ac2aac1c804d4f5719a3513535acdddacc929
openshift-logging/fluentd-rhel8@sha256:fa5bba068d4ebf7624ad20c72af47a984e460bdbfafa90c83b7b78a9113354e2
openshift-logging/kibana6-rhel8@sha256:eb058d7d6145d35624567de74ed139aff8186062a0496663d45b1d6f9b2ae68c
openshift-logging/log-file-metric-exporter-rhel8@sha256:4c0406ba6d9fca3d6d95b9c8f2b9a3c5d4a1c84727800fe0d45bc412d31dd28d
openshift-logging/logging-curator5-rhel8@sha256:dcaf9ccda446a2b6ba0f31eea480c496011a3a2c5751dab7ecd4826c4fe1e897
openshift-logging/logging-loki-rhel8@sha256:d9a90877a5db128fb17576b608a7ee73271939458e2f499629ce5ea43f387964
openshift-logging/logging-view-plugin-rhel8@sha256:ee3d28b620b03e7b2e2e8e87554942515d6022377a66aa0a2d986349dd062639
openshift-logging/loki-rhel8-operator@sha256:e361d6a863f360303a4fd5bf746dce961ac278a645ffb9c6ec87f9a58070f923
openshift-logging/lokistack-gateway-rhel8@sha256:f34b71eb747790497c24715708011a68c050e0149c7561aad6b07315fb6d43c8
openshift-logging/opa-openshift-rhel8@sha256:806aaebf9ab2dc1fd654ccd6915490ab90bf1ad1bb5dd1c434e7af5d475b5ae0
openshift-logging/vector-rhel8@sha256:000cbef2e53822c62a07d9c46bcd368a3ad33b3a8a382be0ad5f6ef47fcd780e

x86_64

openshift-logging/cluster-logging-operator-bundle@sha256:6349e0dfa8a940002570e6a0d5d7b91cf9f1fc2186da823150be95c55e7eec64
openshift-logging/cluster-logging-rhel8-operator@sha256:5484c76cad28fa452c48f67d95295583dfbc6d34db22495eccfffec051893c49
openshift-logging/elasticsearch-operator-bundle@sha256:a846c915cb692856eb1907726dc06c35564da1e40bbec7e1fe05b3b64327b8d4
openshift-logging/elasticsearch-proxy-rhel8@sha256:e18ecc9b852178129fdb2a2efb40f97f6814f6980681ac82eae2eef9a317a96f
openshift-logging/elasticsearch-rhel8-operator@sha256:8f107eed0efa34f6fa00003098457a58c1fd482286f590359a73c39ef225deb7
openshift-logging/elasticsearch6-rhel8@sha256:c0fc4eb8c0283e8cc9b08a1fe1cc49bd498d28d1233affaaf02b338de1cee5e9
openshift-logging/eventrouter-rhel8@sha256:ec95c7ff9c5a13a3cf11e89aff97d792f63cf89fb654f063aa662d134a335ee8
openshift-logging/fluentd-rhel8@sha256:bdb22f54ed17a76cb18e86f0a66ce6a5d1e12996b1c730c188096a78587bc220
openshift-logging/kibana6-rhel8@sha256:fa617e29c09c782bc28c3a7d908be7809537e10fb46beb3fa74b391b90a86efb
openshift-logging/log-file-metric-exporter-rhel8@sha256:6485741ec168a35fae0467dd8e23a74f143cadfd5faa298749bdced24eb7ce3c
openshift-logging/logging-curator5-rhel8@sha256:494df23374cd1164ad802e252228112874083613f616a9beefa0737dd85d00f8
openshift-logging/logging-loki-rhel8@sha256:293d0312079920e56e13c867dfc0f7d296c83db41af840eb01013d6a992afa24
openshift-logging/logging-view-plugin-rhel8@sha256:f54f746094413f0e99c70e1fe31fe867c058c851f63a4512368afc2c26a94795
openshift-logging/loki-operator-bundle@sha256:8cbc36a64caf3e7de5b297976d7029ac88d01aa94da35f0d2601442d23bcdabe
openshift-logging/loki-rhel8-operator@sha256:7a6a51ce23fb6e602c3ae8ceafa1c936fbedfbed49cca867c7e1577b444ec3b2
openshift-logging/lokistack-gateway-rhel8@sha256:3b623354def976e6cc8ffcc6cdefb7573c4d43340733f00236c68870ff9fb1ba
openshift-logging/opa-openshift-rhel8@sha256:f4bfb9910a0c3f6bd73769abea0f8b42e562560d94059a423b2498fb93a7b949
openshift-logging/vector-rhel8@sha256:a4beab96eeafe47c939aef8c17bff4f20bf98ef0c4e5583c7208d07bb27b0586

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility