-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Logging Subsystem for Red Hat OpenShift - 5.5.9 security update Advisory ID: RHSA-2023:1310-01 Product: Logging Subsystem for Red Hat OpenShift Advisory URL: https://access.redhat.com/errata/RHSA-2023:1310 Issue date: 2023-03-29 CVE Names: CVE-2022-4304 CVE-2022-4450 CVE-2022-41717 CVE-2023-0215 CVE-2023-0286 CVE-2023-0767 CVE-2023-23916 ===================================================================== 1. Summary: An update is now available for Logging Subsystem for Red Hat OpenShift - 5.5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Logging Subsystem 5.5.9 - Red Hat OpenShift Security Fix(es): * golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2161274 - CVE-2022-41717 golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests 5. JIRA issues fixed (https://issues.jboss.org/): LOG-3730 - [release-5.5] /var/log/oauth-server/audit.log not being scraped by log collector 6. References: https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-41717 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/cve/CVE-2023-0767 https://access.redhat.com/security/cve/CVE-2023-23916 https://access.redhat.com/security/updates/classification/#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZCT+zdzjgjWX9erEAQiEVw//c5kd+CHap30XTR1eL8R3ImnvW9ZmDGF7 ItrMScIUKbulYWtIs7lzrNQ48sFRWwkI/ue1B97pNUmEqndVwSdKmnOPPmERwS3l UYIUZ7tGRFMHLGKHiatoG4lGQF0ye0g+pz3zgye+r8AkHhq6zb8J5PyqvhYJB+i7 iqOnnx26rQDprJldnwir2N73F0NN6gfU6oLxV2S3OmiRmpQyd4PPd9LX9XVAcS37 aTbOtnWBv1kJMpWiyIEQ4+NECfKP+PzhPpYtp+Aa/wTyJmvy9WhVjXc9+xEC8xRO wTOG+SuNp88b2vbbzHgyhgP4xdbAGWiMqdcTUzBGNb43QN24D8bI9wPMiHMbMrPJ n59MfUrFQ8oBmuBNkHN39nyG4xeqr6EcgdoEvql/w7fipxj7a8wCo3R55OYl/K6L nplZvuhMrHWzjJvN4gsUt5UdvrFLzNy0nJ+BOXHMLOW+chwyLu3MxhMBqMKFFduv rHuPLWgtzh6i2Cw0Zh7RDoEOV0FzNqXP77n12PyX2nm1h9Fu+VRMTBlr8fEAqLtN f8KNjI2txd6i0wRITmr3QEfTt87jbFltxTBwGhpAuI8wQod/NpDy6z4ckoqxacIk XGkCO66c7kjTl6ewiVwaPg84v/Tcu4kV5eWN/i+BTYXnUo6ps36Xajd7K0On9lgz LlzBWtkhNu0= =Iy0e -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce