RHSA-2023:3445: Important: Red Hat OpenStack Platform 16.2 (etcd) security update
A highly-available key value store for shared configurationSecurity Fix(es): Information discosure via debug function (CVE-2021-28235) html/template: improper handling of JavaScript whitespace (CVE-2023-24540) golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) crypto/tls: large handshake records may cause panics (CVE-2022-41724) net/http mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725) net/http net/textproto: denial of service from excessive memory allocation (CVE-2023-24534) net/http net/textproto mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536) go/parser: Infinite loop in parsing (CVE-2023-24537) html/template: backticks not treated as string delimiters (CVE-2023-24538) html/template: improper sanitization of CSS values (CVE-2023-24539) html/template: improper handling of empty HTML attributes (CVE-2023-29400)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3445?
The severity of RHSA-2023:3445 is categorized as critical due to multiple vulnerabilities affecting etcd.
How do I fix RHSA-2023:3445?
To fix RHSA-2023:3445, update etcd to version 3.3.23-14.el8 or the latest version available.
What vulnerabilities are addressed in RHSA-2023:3445?
RHSA-2023:3445 addresses information disclosure via CVE-2021-28235 and improper handling of JavaScript whitespace via CVE-2023-24540.
Which packages are affected by RHSA-2023:3445?
The affected packages include etcd, etcd-debuginfo, and etcd-debugsource with the specified version constraint.
Is there a known exploit for RHSA-2023:3445?
As of the advisory, no public exploit has been reported specifically for the vulnerabilities in RHSA-2023:3445.