RHSA-2023:5969: Important: Red Hat OpenStack Platform 17.1.1 security update
Important: Red Hat OpenStack Platform 17.1.1 security update
Other sources
The etcd packages provide a highly available key-value store for shared configuration.Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5969?
The severity of RHSA-2023:5969 is high.
What software is affected by RHSA-2023:5969?
The affected software includes Red Hat OpenStack Platform 17.1.1, collectd-libpod-stats, etcd, python-octavia-tests-tempest, etcd-debuginfo, etcd-debugsource, python-octavia-tests-tempest-debugsource, python3-octavia-tests-tempest, python3-octavia-tests-tempest-golang, and python3-octavia-tests-tempest-golang-debuginfo.
How severe is the vulnerability in RHSA-2023:5969?
The vulnerability in RHSA-2023:5969 has a severity score of 7 out of 10.
Where can I find more information about RHSA-2023:5969?
You can find more information about RHSA-2023:5969 on the Red Hat Customer Portal and Bugzilla.
How do I fix the vulnerability in RHSA-2023:5969?
To fix the vulnerability in RHSA-2023:5969, apply the security update provided by Red Hat.