Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Service Telemetry Framework 1.5.4
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Service Telemetry Framework 1.5.4
ID: RHSA-2024:1078
Distribution: Red Hat
Plattformen: Red Hat Service Telemetry Framework 1.5 for RHEL 8
Datum: Di, 5. März 2024, 21:17
Referenzen: https://access.redhat.com/errata/RHSA-2024:1078
https://access.redhat.com/security/cve/CVE-2023-39326
https://issues.redhat.com/browse/OSPRH-800
https://access.redhat.com/security/cve/CVE-2023-45287
https://bugzilla.redhat.com/show_bug.cgi?id=2253330
https://issues.redhat.com/browse/OSPRH-2140
https://issues.redhat.com/browse/OSPRH-825
https://issues.redhat.com/browse/OSPRH-3492
https://bugzilla.redhat.com/show_bug.cgi?id=2253193
https://issues.redhat.com/browse/OSPRH-2577
Applikationen: Service Telemetry Framework 1.5.4

Originalnachricht

An update is now available for Service Telemetry Framework 1.5.4.

Red Hat Product Security has rated this update as having a security impact of
Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Security Fix(es):

* golang: net/http/internal: Denial of Service (DoS) via Resource Consumption
via HTTP requests (CVE-2023-39326)
* golang: crypto/tls: Timing Side Channel attack in RSA based TLS key
exchanges. (CVE-2023-45287)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Service Telemetry Framework (STF) provides automated collection of measurements
and data from remote clients, such as Red Hat OpenStack Platform or third-party nodes. STF then transmits the information to a centralized, receiving Red Hat OpenShift Container Platform (OCP) deployment for storage, retrieval, and monitoring.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2023-39326: Uncontrolled Resource Consumption (CWE-400)
CVE-2023-45287: Observable Timing Discrepancy (CWE-208)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung