RHSA-2024:3479: Important: Red Hat OpenStack Platform 16.2 director Operator container images security update
Important: Red Hat OpenStack Platform 16.2 director Operator container images security update
Other sources
Red Hat OpenStack Platform provides the facilities for building, deploying and monitoring a private or public infrastructure-as-a-service (IaaS) cloud running on commonly available physical hardware.The Red Hat OpenStack Platform (RHOSP) director Operator adds the ability to install and run a RHOSP cloud within OpenShift Container Platform (OCP).Security Fix(es): golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326) golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288) golang: x/crypto/ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795) goproxy: Denial of service (DoS) via unspecified vectors (CVE-2023-37788) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3479?
The severity of RHSA-2024:3479 is classified as important.
Which versions of Red Hat OpenStack are affected by RHSA-2024:3479?
RHSA-2024:3479 affects Red Hat OpenStack Platform 16.2.
How do I fix RHSA-2024:3479?
To fix RHSA-2024:3479, you should apply the security updates provided in the advisory.
What is the purpose of the RHSA-2024:3479 update?
The RHSA-2024:3479 update addresses security vulnerabilities in the Red Hat OpenStack Platform 16.2 director Operator container images.
What type of vulnerabilities does RHSA-2024:3479 address?
RHSA-2024:3479 addresses significant security issues that could affect the deployment and operation of OpenStack.