Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:3331 - Security Advisory
Issued:
2024-05-30
Updated:
2024-05-30

RHSA-2024:3331 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: OpenShift Container Platform 4.14.27 bug fix and security update

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Container Platform release 4.14.27 is now available with updates to packages and images that fix several bugs and add enhancements.

This release includes a security update for Red Hat OpenShift Container Platform 4.14.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.

This advisory contains the container images for Red Hat OpenShift Container Platform 4.14.27. See the following advisory for the RPM packages for this release:

https://access.redhat.com/errata/RHBA-2024:3335

Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:

https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

Security Fix(es):

  • golang: net/http, x/net/http2: unlimited number of CONTINUATION frames

causes DoS (CVE-2023-45288)

  • python-gunicorn: HTTP Request Smuggling due to improper validation of

Transfer-Encoding headers (CVE-2024-1135)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html

Solution

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:

https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html

You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.

The sha values for the release are

(For x86_64 architecture)
The image digest is sha256:4d30b359aa6600a89ed49ce6a9a5fdab54092bcb821a25480fdfbc47e66af9ec

(For s390x architecture)
The image digest is sha256:e9c1f125eadb37b95f4f7d33b883bb3b2a2f8fb1fc76ef019d41ce568cc65f32

(For ppc64le architecture)
The image digest is sha256:8ba7ba6c183719007a4d5f8fc221eace8ce3c5d0042b231c49be25a41656aacc

(For aarch64 architecture)
The image digest is sha256:0fed37d60b1d0e28cb3960e1cd53a8ce1c6d1d51abf48d78dac6751a56ec5ed3

All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html

Affected Products

  • Red Hat OpenShift Container Platform 4.14 for RHEL 9 x86_64
  • Red Hat OpenShift Container Platform 4.14 for RHEL 8 x86_64
  • Red Hat OpenShift Container Platform for Power 4.14 for RHEL 9 ppc64le
  • Red Hat OpenShift Container Platform for Power 4.14 for RHEL 8 ppc64le
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 9 s390x
  • Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.14 for RHEL 8 s390x
  • Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 9 aarch64
  • Red Hat OpenShift Container Platform for ARM 64 4.14 for RHEL 8 aarch64

Fixes

  • BZ - 2268273 - CVE-2023-45288 golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS
  • BZ - 2275280 - CVE-2024-1135 python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers
  • OCPBUGS-27394 - [vsphere] IPI destroy cluster failed to delete TagCategory
  • OCPBUGS-28611 - Remove NCv2 series from azure doc tested_instance_types_x86_64
  • OCPBUGS-33537 - [4.14z] slow ovnkube-node initialization on large number of services with externalIps
  • OCPBUGS-33635 - [release-4.14] Masthead logo no longer restricted to a max-height of 60px
  • OCPBUGS-33640 - Topology links between VMs and non VMs (such as Pod or Deployment) don't show
  • OCPBUGS-33798 - FailedPrecondition volume does not appear staged

CVEs

  • CVE-2023-45288
  • CVE-2024-1135
  • CVE-2024-28834
  • CVE-2024-28835

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift4/driver-toolkit-rhel9@sha256:02f4854c8a2ac829fa497f433f52e39a8b2a2c5230a2c14193080510dba95552
openshift4/network-tools-rhel8@sha256:d12787bea010edfd8a6072dfbc61880ec8df8b4bee0a5a38b83e2e9a04cad342
openshift4/ose-agent-installer-node-agent-rhel9@sha256:2288fc3efbd342efb4066d6f1e9d296939b9ca3485ec49ffd683fab80942cef2
openshift4/ose-agent-installer-utils-rhel9@sha256:b9f10623f9400e59c9ab8eaab08d422a3eb5fd2a9c32f02547f741ca3a3d38f1
openshift4/ose-baremetal-installer-rhel8@sha256:d81bedd24ef68bab60a00620923a02ed9666ee3089ea175624524c2af29f4502
openshift4/ose-cluster-autoscaler-operator@sha256:3e39ad193ce8732aeb73f4e903c0f8e8f43abb7590ae9c848f5f2d68d4921743
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:50a34f4cdb25748514ca688375bfc4ef3ed379818243214e62dd3360be44aa71
openshift4/ose-cluster-node-tuning-operator@sha256:50a34f4cdb25748514ca688375bfc4ef3ed379818243214e62dd3360be44aa71
openshift4/ose-console@sha256:707894993c637779dde870d1cbc733341768432d3beae45f14b096722c1d7635
openshift4/ose-etcd-rhel9@sha256:1b12181214ad990931de365eecb7efe4ab34a3147cdafcc296298d35a4f7d83a
openshift4/ose-haproxy-router@sha256:4f2d626eb400b444700a80c2efdf29ba93872abc0620285623b05525c1fffa8a
openshift4/ose-hyperkube-rhel9@sha256:33b5df4508533d6ae6578872c23c8a781934cb9bf89a71fd6324739d318f728a
openshift4/ose-hypershift-rhel8@sha256:dbb8b22c262f41a2178815e05bbe903cc578858b562f401fb9a229d1c7188de8
openshift4/ose-installer@sha256:dde17bfcd61fbed0cbe7764c6c827d79f7e4f5161f7182dbdf8044ce3ae00d71
openshift4/ose-installer-artifacts@sha256:ed28b865ed1657cdf1d2acb5287fe2012845dc409a9cdccd24b652b2601e0e48
openshift4/ose-ironic-agent-rhel9@sha256:93289317cd0234b16892634e63e32f9e866f00c398776cc281946e3ae9073c0f
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:b5d0d2a59bdbce92419b4a60aa386c1ee098fd55d35622dd5fe795c5f214a526
openshift4/ose-ironic-rhel9@sha256:c8c0b9ae7c1988326b812eec034e9065cd305ae6a927cd81138e3687ef45ec38
openshift4/ose-ironic-static-ip-manager-rhel9@sha256:43d49a2d653ad655864c737183857b14903cddcee8f3367bb0b718b5f2a544b2
openshift4/ose-machine-api-operator@sha256:a07305e4d8731662f4f74b672bcb658e5b53593a08c1768da52577670eae80a8
openshift4/ose-machine-os-images-rhel8@sha256:f65de2fa7102e01a69cf096fca9b681f9c4f3f520cc2858e70b70b2bc9d9cdfa
openshift4/ose-ovn-kubernetes-rhel9@sha256:27bb95bed6d1a16dfbcaea7edd77192cabe738555e904522bac2ef2018e7655c
openshift4/ose-ovn-kubernetes@sha256:27bb95bed6d1a16dfbcaea7edd77192cabe738555e904522bac2ef2018e7655c
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:dd31fee892859c2f92004de16416718714bdf677fdd5d52cda32d42e5a6388e6
openshift4/ose-pod@sha256:9970b387ce2b37cc806d5079274f82d6c3c0ee5de5d9a0b28bafcac7f40580bd

ppc64le

openshift4/driver-toolkit-rhel9@sha256:c8e04075d322724a81051290db2b36914ee8d8fd06f1f9c28377142465caa6a6
openshift4/network-tools-rhel8@sha256:17ad9e6e79cfde04c5e4bb2be1cccd4b82328938b59edb91834b0458a29e3a87
openshift4/ose-agent-installer-node-agent-rhel9@sha256:02430a1170b02a2029b95b62ba7079ad5b09e9c0ec17175027d5b503bb289c5c
openshift4/ose-agent-installer-utils-rhel9@sha256:0aa0651c884c16f456894c11c96a411c6564988861519fd77506754ebe79ffbd
openshift4/ose-baremetal-installer-rhel8@sha256:b959cea9c22829ada32fc4efa55265153952b3be5da430132aa8880d88f8338d
openshift4/ose-cluster-autoscaler-operator@sha256:d0d9c15acde214d2b88f6fac223aa3622b36b06fa9fc2ae6a1a8a775fa544166
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:be407bccfcbdaa82015c867efb9b038d3c14770bcebc4636d889f41afe65914e
openshift4/ose-cluster-node-tuning-operator@sha256:be407bccfcbdaa82015c867efb9b038d3c14770bcebc4636d889f41afe65914e
openshift4/ose-console@sha256:ea96f8422cccf70ce686a0888c99351042915107618d2868e0f2f999f5308f84
openshift4/ose-etcd-rhel9@sha256:3b7db706149595adbb0f3ffabfeafaf9d329d2f89706fb9de20a24f528cbcabc
openshift4/ose-haproxy-router@sha256:caa466464773edbc5b67a29e4fbdc33a87550df0c92e351605f80db22a3038b0
openshift4/ose-hyperkube-rhel9@sha256:d31811e350f24fad1773561c6e145de8e6ff9a898496a5807b4367fbc442800b
openshift4/ose-hypershift-rhel8@sha256:a90cd04bcf7385b7aa7d273c6a5b1a579aa4fd99ea4c25abd6ef7dc02835aec1
openshift4/ose-installer@sha256:7ebbce099af34c40bba4dac1daa07ef734374294b3ac3b31b48d8890c2bedbd5
openshift4/ose-installer-artifacts@sha256:40c5865e32371ae5b401471f14964c16d712badb5225dcc1b178f4b75d40f742
openshift4/ose-machine-api-operator@sha256:2d2d3191e843817cb48d08fb23622dbbb9e6899280e2f2d7b779149d33176a33
openshift4/ose-machine-os-images-rhel8@sha256:d45386a3e70db4fc9a23c45fa0971361c75eef8e2f3dcf9da684c744568bc0a4
openshift4/ose-ovn-kubernetes-rhel9@sha256:ff3575c93ae90fc2e3f489ec74ac240357b5d71d5793aedc855d39ed58101c5c
openshift4/ose-ovn-kubernetes@sha256:ff3575c93ae90fc2e3f489ec74ac240357b5d71d5793aedc855d39ed58101c5c
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:99dee0b732d4f8970eab77c13d825914d1e223822a4d132fa47c78678c8dad09
openshift4/ose-pod@sha256:7a2c108eda122c89d401e618bbca05252b913724f3f43b47ccf080b053229a96

s390x

openshift4/driver-toolkit-rhel9@sha256:6e25f541de9ad53e8c7a3b4a275b49982e24ff10a2913300504e14c1f488288f
openshift4/network-tools-rhel8@sha256:03c12c7a04c36a795378d09378b5d47e659442e8e8b9aeccca30dc0fe2eb6038
openshift4/ose-agent-installer-node-agent-rhel9@sha256:f14613d6e2a6082539b34ab5a97af96cece75778c5aaff79f4a05814546c7d8e
openshift4/ose-agent-installer-utils-rhel9@sha256:e741a9543c853313f16c6fd3a30c187f9aa274d9570e035f842267314097da22
openshift4/ose-baremetal-installer-rhel8@sha256:0a600ebd6495daea79a53cbf136adb3866e6406f7e6615ac136103c8eb821043
openshift4/ose-cluster-autoscaler-operator@sha256:f93a29b2665dd9423966162461c32756322c44b01c358ff3eacc57fb0f7a0048
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c8b34839c66c8bb190790dbfebc9f81bbb5c4e758df4d1ad49154a9bc9e09620
openshift4/ose-cluster-node-tuning-operator@sha256:c8b34839c66c8bb190790dbfebc9f81bbb5c4e758df4d1ad49154a9bc9e09620
openshift4/ose-console@sha256:63c94b40b52b73bcbba7b69c267055e4649d4b104036acb11caa461b77718ced
openshift4/ose-etcd-rhel9@sha256:09a1af0f7ac31d220a15c05c1fc8ff50e57b77f62f5dae6e3dfa87d7ba63f0d2
openshift4/ose-haproxy-router@sha256:7d2c004c7567b0203ac9eb16b06971b0e0e36986ab09da7e90f80db6815866c6
openshift4/ose-hyperkube-rhel9@sha256:159fb1cf2b2bfb1d6ea265619b4f281c73f29effbf82176adbbc43ff606558d2
openshift4/ose-hypershift-rhel8@sha256:3545ce63ecd97d9ce0bd20e77cdcde6952e59ca962baf66db5a198d16d7c5681
openshift4/ose-installer@sha256:5e5b08bdfcd33d89cf57a4efdb7aab9c9dda994f82221566ddaae76f54c8fb11
openshift4/ose-installer-artifacts@sha256:b45e946749f9b777c0bf0b0e62076bf9b8572e8026d6edc13307ffb2969b4b10
openshift4/ose-machine-api-operator@sha256:f8ccce665a728bdffb7b26c76bb2f19bde99f7131cb01462d868e15399c02be4
openshift4/ose-ovn-kubernetes-rhel9@sha256:6873d858751a440eb7d159e0743b8a6e66e40de20eb6a6532cedcaa2cc451dac
openshift4/ose-ovn-kubernetes@sha256:6873d858751a440eb7d159e0743b8a6e66e40de20eb6a6532cedcaa2cc451dac
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:d648d2d83769d09a3c15a189dd7c3ea66c81365b9944a1d28da3707c38de39c0
openshift4/ose-pod@sha256:8f9a4cdd1ff7e3f3cfe8d3be109bfe36f9743b6149a8d4fb2160ed2d4ef60c8d

x86_64

openshift4/driver-toolkit-rhel9@sha256:4feae2e6bb59f667431e11e832d294fc5900c1ab38a3bb845191ee93524208e4
openshift4/network-tools-rhel8@sha256:b98c393c434204abe7b8eda190ed072bb74e349728a438a28f243cfff6135931
openshift4/ose-agent-installer-node-agent-rhel9@sha256:933a16569c4c19d5264e31acb6ef7184c80410227f8b5bbff57ee62dfb2d6956
openshift4/ose-agent-installer-utils-rhel9@sha256:c294d0e0a08c16b1ec0a2fca681c2e95a95e5a2fbdd73d866ca006fe65225c99
openshift4/ose-baremetal-installer-rhel8@sha256:ddc445eeee2bf0ae040b83ef0a098854821216be3b1a08a497561ae53bdd6581
openshift4/ose-cluster-autoscaler-operator@sha256:ad18da2c0f3bbcf912d3fe0cba164cf0365120841ec67fa8c79945eb0694432b
openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:23b51e53985b50d0c528358d5557b12ac2897fa020bd92e61c7d4fd1e683e993
openshift4/ose-cluster-node-tuning-operator@sha256:23b51e53985b50d0c528358d5557b12ac2897fa020bd92e61c7d4fd1e683e993
openshift4/ose-console@sha256:3cfd3e8f7e91da7ea25fc3e0f142dc34ef43165ddc724203bae26a8967041b41
openshift4/ose-etcd-rhel9@sha256:f86a26f09f2fc6f9fc5b69e077d5a7d0c514235b020f3ede2383510718ef3827
openshift4/ose-haproxy-router@sha256:f699172cd627b0babbc67878fd78883648a1f8bd9c82441e875b67a9c8f5b71a
openshift4/ose-hyperkube-rhel9@sha256:bc093a8ded0afe2024a90acd6ef0e1a20c717eabfc80c08e585f823cd10327ea
openshift4/ose-hypershift-rhel8@sha256:0aa879f731211c3b80924f0ad5c2d46bf840ad5d157607918afcd88aad067988
openshift4/ose-installer@sha256:a145cef307f12d62a5837415eb63f48a9e0500c22f6a85279a9d9adfb83c8a18
openshift4/ose-installer-artifacts@sha256:7b157d81a96a58b59e3fb7231bfe8c79cd9c81dbbbd8fe593eed150909c3ba26
openshift4/ose-ironic-agent-rhel9@sha256:9753acf4ed59d48130b0e6a0caef62e1b5caba4c23ca05b8c80256d85f31f3f9
openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:1a3bf3549f14452bd745dcb51f34c32ad66813118b554c16aac8283b0965abdc
openshift4/ose-ironic-rhel9@sha256:2a660b348d98513c3e5ed390f58a4a8830e56027c35645eedc8067618703775a
openshift4/ose-ironic-static-ip-manager-rhel9@sha256:3ddf304d2bcc76743540536e57af9c459dd1fb63a127a07b128074a42b992300
openshift4/ose-machine-api-operator@sha256:7525f7f7ed6372b8ae82da56e4cd6f90be5019ef88024f3f9f4d9a286f095ea3
openshift4/ose-machine-os-images-rhel8@sha256:bb989e948b726b77227501fba85a35008d8f3f7f303f03f125ea85f6a61d7469
openshift4/ose-ovn-kubernetes-rhel9@sha256:77be9fe8d3307c1fdfb6469a4fb7ce84190ac1727cbb04cc374be34cac0649ba
openshift4/ose-ovn-kubernetes@sha256:77be9fe8d3307c1fdfb6469a4fb7ce84190ac1727cbb04cc374be34cac0649ba
openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:33745f0814b401a1dfd89ba9bdf374e52521f175d0578cab4900afbd70eff3cb
openshift4/ose-pod@sha256:0f6ec1e4ec9138491cd9c6b49038c49eabc1e9116a25e5be6ddc709a36339383
openshift4/ose-vsphere-csi-driver-rhel8@sha256:0b9ca6dafacfb20c41762a915e99868e2ef73cbb18e18724c2e0bdb44a417620
openshift4/ose-vmware-vsphere-csi-driver-rhel8@sha256:0b9ca6dafacfb20c41762a915e99868e2ef73cbb18e18724c2e0bdb44a417620
openshift4/ose-vsphere-csi-driver-syncer-rhel8@sha256:6121a5e12032d52d11d25e8252023fb70ce10a6f1d779a9e0af314f199aa9e6d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat, Inc.

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility