VDB
RHSA-2024%3A2930
RHSA-2024%3A2930
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/logging-loki-rhel8@sha256:293d0312079920e56e13c867dfc0f7d296c83db41af840eb01013d6a992afa24_amd64 as a component of RHOL 5.7 for RHEL 8 | * |
| Red Hat | openshift-logging/logging-view-plugin-rhel8@sha256:ee3d28b620b03e7b2e2e8e87554942515d6022377a66aa0a2d986349dd062639_s390x as a component of RHOL 5.7 for RHEL 8 | openshift-logging/logging-view-plugin-rhel8@sha256:ee3d28b620b03e7b2e2e8e87554942515d6022377a66aa0a2d986349dd062639_s390x |
| Red Hat | openshift-logging/kibana6-rhel8@sha256:c92d7b58be4a5dd715101723b187cf930e7b86ffa6e7a7b3119b7512c0f68639_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/kibana6-rhel8@sha256:c92d7b58be4a5dd715101723b187cf930e7b86ffa6e7a7b3119b7512c0f68639_arm64 |
| Red Hat | openshift-logging/cluster-logging-operator-bundle@sha256:6349e0dfa8a940002570e6a0d5d7b91cf9f1fc2186da823150be95c55e7eec64_amd64 as a component of RHOL 5.7 for RHEL 8 | * |
| Red Hat | openshift-logging/elasticsearch-rhel8-operator@sha256:8f107eed0efa34f6fa00003098457a58c1fd482286f590359a73c39ef225deb7_amd64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/elasticsearch-rhel8-operator@sha256:8f107eed0efa34f6fa00003098457a58c1fd482286f590359a73c39ef225deb7_amd64 |
| Red Hat | openshift-logging/loki-rhel8-operator@sha256:48af23673bf8432a192fed8ab9cb9f4a633ef8f26293253c268bc46360bb835e_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/loki-rhel8-operator@sha256:48af23673bf8432a192fed8ab9cb9f4a633ef8f26293253c268bc46360bb835e_arm64 |
| Red Hat | openshift-logging/logging-view-plugin-rhel8@sha256:1493fa1da9844aec3b3cb7506d40cc457aeef5204b5441cae47dbdb6a9ab249b_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/logging-view-plugin-rhel8@sha256:1493fa1da9844aec3b3cb7506d40cc457aeef5204b5441cae47dbdb6a9ab249b_arm64 |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:1ddec93f26b66624a8ffc6d6af6141f71df2bd0661f3038d327c787d1b61edd1_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/log-file-metric-exporter-rhel8@sha256:1ddec93f26b66624a8ffc6d6af6141f71df2bd0661f3038d327c787d1b61edd1_arm64 |
| Red Hat | openshift-logging/kibana6-rhel8@sha256:eb058d7d6145d35624567de74ed139aff8186062a0496663d45b1d6f9b2ae68c_s390x as a component of RHOL 5.7 for RHEL 8 | openshift-logging/kibana6-rhel8@sha256:eb058d7d6145d35624567de74ed139aff8186062a0496663d45b1d6f9b2ae68c_s390x |
| Red Hat | openshift-logging/logging-loki-rhel8@sha256:f5f7a3f069eb73b92aeaff8b8a6ad55459eb526928491abb0589b28017fbe705_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/logging-loki-rhel8@sha256:f5f7a3f069eb73b92aeaff8b8a6ad55459eb526928491abb0589b28017fbe705_arm64 |
| Red Hat | openshift-logging/fluentd-rhel8@sha256:4dbb10ac48ebedcd08e4d93d7958876d7c489b3c0764a703979c4cc16b2faef5_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/fluentd-rhel8@sha256:4dbb10ac48ebedcd08e4d93d7958876d7c489b3c0764a703979c4cc16b2faef5_arm64 |
| Red Hat | openshift-logging/vector-rhel8@sha256:f635cf3c647aeb72a6af00d97b4966dae041fe8d42722bded29c0de31181a7f0_arm64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/vector-rhel8@sha256:f635cf3c647aeb72a6af00d97b4966dae041fe8d42722bded29c0de31181a7f0_arm64 |
| Red Hat | openshift-logging/fluentd-rhel8@sha256:bdb22f54ed17a76cb18e86f0a66ce6a5d1e12996b1c730c188096a78587bc220_amd64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/fluentd-rhel8@sha256:bdb22f54ed17a76cb18e86f0a66ce6a5d1e12996b1c730c188096a78587bc220_amd64 |
| Red Hat | openshift-logging/eventrouter-rhel8@sha256:ec95c7ff9c5a13a3cf11e89aff97d792f63cf89fb654f063aa662d134a335ee8_amd64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/eventrouter-rhel8@sha256:ec95c7ff9c5a13a3cf11e89aff97d792f63cf89fb654f063aa662d134a335ee8_amd64 |
| Red Hat | openshift-logging/elasticsearch6-rhel8@sha256:1c6c3634aae0f7a47fba4f1a06530e742a0042896291579642a605b53105c019_s390x as a component of RHOL 5.7 for RHEL 8 | * |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel8@sha256:dbeff8644fe3cfe045e9658eae6d697fe2ddb979ccf06952fc955ebe1aa0aa3e_ppc64le as a component of RHOL 5.7 for RHEL 8 | * |
| Red Hat | openshift-logging/loki-rhel8-operator@sha256:7a6a51ce23fb6e602c3ae8ceafa1c936fbedfbed49cca867c7e1577b444ec3b2_amd64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/loki-rhel8-operator@sha256:7a6a51ce23fb6e602c3ae8ceafa1c936fbedfbed49cca867c7e1577b444ec3b2_amd64 |
| Red Hat | openshift-logging/elasticsearch-proxy-rhel8@sha256:e18ecc9b852178129fdb2a2efb40f97f6814f6980681ac82eae2eef9a317a96f_amd64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/elasticsearch-proxy-rhel8@sha256:e18ecc9b852178129fdb2a2efb40f97f6814f6980681ac82eae2eef9a317a96f_amd64 |
| Red Hat | openshift-logging/vector-rhel8@sha256:cc9253be2cdbceaf8ec120aabc9f4fdd603f3b9ec190c24fd05e95f2863b5ea9_ppc64le as a component of RHOL 5.7 for RHEL 8 | openshift-logging/vector-rhel8@sha256:cc9253be2cdbceaf8ec120aabc9f4fdd603f3b9ec190c24fd05e95f2863b5ea9_ppc64le |
| Red Hat | openshift-logging/elasticsearch6-rhel8@sha256:c0fc4eb8c0283e8cc9b08a1fe1cc49bd498d28d1233affaaf02b338de1cee5e9_amd64 as a component of RHOL 5.7 for RHEL 8 | openshift-logging/elasticsearch6-rhel8@sha256:c0fc4eb8c0283e8cc9b08a1fe1cc49bd498d28d1233affaaf02b338de1cee5e9_amd64 |
…and 43 more
Timeline
- May 23, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:2930 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://issues.redhat.com/browse/LOG-5472 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2930.json advisory
- https://access.redhat.com/security/cve/CVE-2023-45288 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-45288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45288 advisory
- https://nowotarski.info/http2-continuation-flood/ advisory
- https://pkg.go.dev/vuln/GO-2024-2687 advisory
- https://www.kb.cert.org/vuls/id/421644 advisory