RHSA-2023:6165: Important: skupper-cli and skupper-router security update
Important: skupper-cli and skupper-router security update
Other sources
Security Fix(es): golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:6165?
The severity of RHSA-2023:6165 is high.
What software is affected by RHSA-2023:6165?
The skupper-cli and skupper-router software is affected by RHSA-2023:6165.
How can I fix the vulnerability RHSA-2023:6165?
You can fix the vulnerability RHSA-2023:6165 by updating skupper-cli and skupper-router to version 1.4.3-4.el9 or 2.4.3-1.el9.
Where can I find more information about RHSA-2023:6165?
You can find more information about RHSA-2023:6165 on the Red Hat website: https://access.redhat.com/errata/RHSA-2023:6165.
Are there any known bugs related to RHSA-2023:6165?
Yes, there are known bugs related to RHSA-2023:6165. You can find more information about them on Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2242803 and https://bugzilla.redhat.com/show_bug.cgi?id=2243296.