VDB
RHSA-2024%3A2933
RHSA-2024%3A2933
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:d80ef1784f96465d305c50888176db38b2566e9991769b25445d485d47ada5b4_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:d80ef1784f96465d305c50888176db38b2566e9991769b25445d485d47ada5b4_ppc64le |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:9ce41fbe39e9483f854bcbffee9799f219aea90796062b2bd11be3440a9de525_arm64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/eventrouter-rhel9@sha256:9ce41fbe39e9483f854bcbffee9799f219aea90796062b2bd11be3440a9de525_arm64 |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:47bff7b6c79af4793cd04cbec1f0a28ec2eef0d0f11dfe86aea87fafc369be64_amd64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/fluentd-rhel9@sha256:47bff7b6c79af4793cd04cbec1f0a28ec2eef0d0f11dfe86aea87fafc369be64_amd64 |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:aaf2dd9162077621883a3b52bd87fe3a6a86275f3fc45dafe494ab1f97b62f5a_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/fluentd-rhel9@sha256:aaf2dd9162077621883a3b52bd87fe3a6a86275f3fc45dafe494ab1f97b62f5a_ppc64le |
| Red Hat | openshift-logging/logging-view-plugin-rhel9@sha256:713be73184bd943c98edd0761eae838c73ef3e2ad3c54d5236c70fe4ed62e073_arm64 as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/vector-rhel9@sha256:f11cd33e6565579f4391276a875dc736e94c9da18a5ed4685d9017d48dc083e0_arm64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/vector-rhel9@sha256:f11cd33e6565579f4391276a875dc736e94c9da18a5ed4685d9017d48dc083e0_arm64 |
| Red Hat | openshift-logging/vector-rhel9@sha256:7a55232ce85ddad2b40040eb105df730d812e421ac03a6377544e576e90ad006_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/vector-rhel9@sha256:7a55232ce85ddad2b40040eb105df730d812e421ac03a6377544e576e90ad006_ppc64le |
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:b681e152d1534c53b3c0eec088060dc2af74d5be33136ae7c2e19cad3d88d829_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/cluster-logging-rhel9-operator@sha256:b681e152d1534c53b3c0eec088060dc2af74d5be33136ae7c2e19cad3d88d829_s390x |
| Red Hat | openshift-logging/logging-loki-rhel9@sha256:d7a273e837f49536edc95f79fff0cefad5419717518390433200e7cbbe299194_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/logging-loki-rhel9@sha256:d7a273e837f49536edc95f79fff0cefad5419717518390433200e7cbbe299194_ppc64le |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:4d9d91f06898e4fe73873c29ab7caf6f5a27647d88b323eda65d64ddeba89d7b_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:4d9d91f06898e4fe73873c29ab7caf6f5a27647d88b323eda65d64ddeba89d7b_ppc64le |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:0c49b5b637eb960dfefbd22855f2a29690564d93b8afe52f0a437a85be919a61_s390x as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:de02ae0bf1936e581f2c094188885a6678487e291874f601a403b57a06cddb2f_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:de02ae0bf1936e581f2c094188885a6678487e291874f601a403b57a06cddb2f_s390x |
| Red Hat | openshift-logging/loki-operator-bundle@sha256:68dd8394cf3f44d9827cb7b8976044e23d92349262334c8def4b2d15cde7a8e3_amd64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/loki-operator-bundle@sha256:68dd8394cf3f44d9827cb7b8976044e23d92349262334c8def4b2d15cde7a8e3_amd64 |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:5d72c559dc381d3fc815f54b5491be0a72e193e31bf800e337e19ba5d6a98746_arm64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:5d72c559dc381d3fc815f54b5491be0a72e193e31bf800e337e19ba5d6a98746_arm64 |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:1d78020e8f3a383caee4e1ef7b94eabf064a79b6bf6eee75630c370d692a4f02_amd64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:1d78020e8f3a383caee4e1ef7b94eabf064a79b6bf6eee75630c370d692a4f02_amd64 |
| Red Hat | openshift-logging/logging-loki-rhel9@sha256:249cf561231b5a793354263fd859382229a2c700639367ba8e12979385431349_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/logging-loki-rhel9@sha256:249cf561231b5a793354263fd859382229a2c700639367ba8e12979385431349_s390x |
| Red Hat | openshift-logging/lokistack-gateway-rhel9@sha256:ab621b9f3ac6390e0457a7bb362be27dd071092ba247d34e341a827d392ec547_arm64 as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:4974a3ced8c308d257e52162ff0c40f562650965d27df34cb6110fb6ccee7733_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/loki-rhel9-operator@sha256:4974a3ced8c308d257e52162ff0c40f562650965d27df34cb6110fb6ccee7733_s390x |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:095068a422f174e35e3dfa16dc424c13e6dba5c59d2469a18fc08a1cf450e9e4_arm64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/loki-rhel9-operator@sha256:095068a422f174e35e3dfa16dc424c13e6dba5c59d2469a18fc08a1cf450e9e4_arm64 |
| Red Hat | openshift-logging/lokistack-gateway-rhel9@sha256:8d7bd7a959c3d645fad27dafa83aa3267891f6c92c359be2d3e679b516b37491_amd64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/lokistack-gateway-rhel9@sha256:8d7bd7a959c3d645fad27dafa83aa3267891f6c92c359be2d3e679b516b37491_amd64 |
…and 22 more
Timeline
- May 23, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:2933 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://issues.redhat.com/browse/LOG-4910 advisory
- https://issues.redhat.com/browse/LOG-5156 advisory
- https://issues.redhat.com/browse/LOG-5308 advisory
- https://issues.redhat.com/browse/LOG-5426 advisory
- https://issues.redhat.com/browse/LOG-5466 advisory
- https://issues.redhat.com/browse/LOG-5504 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2933.json advisory
- https://access.redhat.com/security/cve/CVE-2023-45288 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-45288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45288 advisory
- https://nowotarski.info/http2-continuation-flood/ advisory
- https://pkg.go.dev/vuln/GO-2024-2687 advisory
- https://www.kb.cert.org/vuls/id/421644 advisory