RHSA-2024:0746: Important: new container image: rhceph-5.3
Important: new container image: rhceph-5.3
Other sources
Red Hat Ceph Storage is a scalable, open, software-defined storage platform<br>that combines the most stable version of the Ceph storage system with a<br>Ceph management platform, deployment utilities, and support services.<br>This updated container image is based on Red Hat Ceph Storage 5.3 and Red<br>Hat Enterprise Linux.<br>Space precludes documenting all of these changes in this advisory. Users<br>are directed to the Red Hat Ceph Storage Release Notes for information on<br>the most significant of these changes:<br><a href="https://access.redhat.com/documentation/en-us/redhatcephstorage/5.3/html/releasenotes/index" target="blank">https://access.redhat.com/documentation/en-us/redhatcephstorage/5.3/html/releasenotes/index</a> All users of Red Hat Ceph Storage are advised to pull these new images from<br>the Red Hat Ecosystem catalog.<br>Security Fix(es):<br><li> grafana: Use of Cache Containing Sensitive Information (CVE-2022-23498)</li> <li> grafana: cross site scripting (CVE-2023-0507)</li> <li> grafana: cross site scripting (CVE-2023-0594)</li> <li> haproxy: request smuggling attack in HTTP/1 header parsing (CVE-2023-25725)</li> <li> golang: net/<a href="http:" target="blank">http:</a> excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)</li> <li> haproxy: segfault DoS (CVE-2023-0056)</li> <li> grafana: JWT token leak to data source (CVE-2023-1387)</li> <li> grafana: stored XSS vulnerability affecting the core plugin "Text" (CVE-2023-22462)</li> <li> golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0746?
The severity of RHSA-2024:0746 is classified as important.
How do I fix RHSA-2024:0746?
To fix RHSA-2024:0746, update your Red Hat Ceph Storage to the latest container image as per the advisory.
Which products are affected by RHSA-2024:0746?
The affected products for RHSA-2024:0746 include Red Hat Ceph Storage (MON), Red Hat Ceph Storage (OSD), and Red Hat Enterprise Linux for x86_64.
What is the purpose of RHSA-2024:0746?
RHSA-2024:0746 provides an updated container image with enhancements and security fixes for Red Hat Ceph Storage.
Is there a strong recommendation for RHSA-2024:0746?
It is strongly recommended to update to the fixed version provided in the advisories to mitigate potential vulnerabilities.