RHSA-2023:0786: Important: Network observability 1.1.0 security update
Network observability is an OpenShift operator that provides a monitoring<br>pipeline to collect and enrich network flows that are produced by the<br>Network observability eBPF agent.<br>The operator provides dashboards, metrics, and keeps flows accessible in a<br>queryable log store, Grafana Loki. When a FlowCollector is deployed, new<br>dashboards are available in the Console.<br>Security Fix(es):<br><li> network-observability-console-plugin-container: setting Loki authToken configuration to DISABLE or HOST mode leads to authentication longer being enforced (CVE-2023-0813)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0786?
The severity of RHSA-2023:0786 is classified as medium.
How do I fix RHSA-2023:0786?
To fix RHSA-2023:0786, you need to apply the latest updates for the Network observability operator in your OpenShift environment.
What systems are affected by RHSA-2023:0786?
RHSA-2023:0786 affects the OpenShift platform, specifically the Network observability operator.
What does RHSA-2023:0786 address?
RHSA-2023:0786 addresses vulnerabilities related to network flow monitoring and data collection in OpenShift.
Is there a workaround for RHSA-2023:0786?
Currently, applying the recommended updates is the best approach, and there are no known workarounds for RHSA-2023:0786.