VDB
RHSA-2024%3A3680
RHSA-2024%3A3680
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-service-mesh/pilot-rhel8@sha256:627bacea3ea3ec3b09ff3c60f85e4999223386fda05c013bcab81cff5b4040ba_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/pilot-rhel8@sha256:627bacea3ea3ec3b09ff3c60f85e4999223386fda05c013bcab81cff5b4040ba_arm64 |
| Red Hat | openshift-service-mesh/kiali-rhel8@sha256:d5864a73a82fc6029cbc94bb64d12e09f10945d1e1769c5456a4f304bb3d3ada_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8@sha256:d5864a73a82fc6029cbc94bb64d12e09f10945d1e1769c5456a4f304bb3d3ada_amd64 |
| Red Hat | openshift-service-mesh/grafana-rhel8@sha256:0e955cc01c93bbc46266780fd09b6a4587002202a3bf5a4efb589755f4fcc4b0_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/grafana-rhel8@sha256:0e955cc01c93bbc46266780fd09b6a4587002202a3bf5a4efb589755f4fcc4b0_s390x |
| Red Hat | openshift-service-mesh/prometheus-rhel8@sha256:1df4efcf6677bab8fac4cc82cc19687d78eb0fdc12dcff0b71a5c4e9400a6211_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/prometheus-rhel8@sha256:1df4efcf6677bab8fac4cc82cc19687d78eb0fdc12dcff0b71a5c4e9400a6211_amd64 |
| Red Hat | openshift-service-mesh/ratelimit-rhel8@sha256:a384fd5773eaed50640d9c9ac463ffb34dc5022b8ec9a4d111ce598397064e19_arm64 as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/ratelimit-rhel8@sha256:b808268ee362145269e5f2420e2a0e05897660766e8f2ecc45aacfdc17e9eb4d_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/ratelimit-rhel8@sha256:b808268ee362145269e5f2420e2a0e05897660766e8f2ecc45aacfdc17e9eb4d_ppc64le |
| Red Hat | openshift-service-mesh/pilot-rhel8@sha256:ce61048850e09a80a88a2a515d7cb9420ed843dc063b3fdb06bf58b399709fe1_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/pilot-rhel8@sha256:ce61048850e09a80a88a2a515d7cb9420ed843dc063b3fdb06bf58b399709fe1_ppc64le |
| Red Hat | openshift-service-mesh/kiali-rhel8@sha256:586b1b34b5164306c62c1372bbf666e254183055edf355c676c54e0144094555_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/prometheus-rhel8@sha256:e7607f4c476972bdab679380d3445d5fce52c1c9a152dc2f2c8d05bd2639af43_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/prometheus-rhel8@sha256:e7607f4c476972bdab679380d3445d5fce52c1c9a152dc2f2c8d05bd2639af43_arm64 |
| Red Hat | openshift-service-mesh/pilot-rhel8@sha256:4d4a777974f068d538589cb5bed9ed21ce98038a682548e321f1beefdc55776e_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/pilot-rhel8@sha256:4d4a777974f068d538589cb5bed9ed21ce98038a682548e321f1beefdc55776e_s390x |
| Red Hat | openshift-service-mesh/istio-must-gather-rhel8@sha256:88713f86a767b31a5bbc06a166b6fc2fbcbebd993fa6a661e6aaaa8feea8e112_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/istio-must-gather-rhel8@sha256:88713f86a767b31a5bbc06a166b6fc2fbcbebd993fa6a661e6aaaa8feea8e112_arm64 |
| Red Hat | openshift-service-mesh/grafana-rhel8@sha256:a3bb5c51d37acad8ca8b79c65db4802a0f45ef55837e2ea2fe37ad5bdbe83209_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/grafana-rhel8@sha256:a3bb5c51d37acad8ca8b79c65db4802a0f45ef55837e2ea2fe37ad5bdbe83209_arm64 |
| Red Hat | openshift-service-mesh/grafana-rhel8@sha256:46fdfa161b0729c45aaa032ff9b4b271fef9127bb9acc00c96c9d99cf4b0ce9f_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/grafana-rhel8@sha256:46fdfa161b0729c45aaa032ff9b4b271fef9127bb9acc00c96c9d99cf4b0ce9f_ppc64le |
| Red Hat | openshift-service-mesh/proxyv2-rhel8@sha256:3fac99ca767649b893ab9096394942eac585a1e9f90d97734c67030792c1492a_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8@sha256:3fac99ca767649b893ab9096394942eac585a1e9f90d97734c67030792c1492a_s390x |
| Red Hat | openshift-service-mesh/kiali-rhel8@sha256:1b2f64166729c8a5b60d7e6eff5a8566c1b1a0809dae95d304769a8823203d76_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8@sha256:1b2f64166729c8a5b60d7e6eff5a8566c1b1a0809dae95d304769a8823203d76_s390x |
| Red Hat | openshift-service-mesh/proxyv2-rhel8@sha256:5bd8061225ceaba7191351806531e76da9955fa1cbfd384d9988424f9622f59d_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8@sha256:5bd8061225ceaba7191351806531e76da9955fa1cbfd384d9988424f9622f59d_amd64 |
| Red Hat | openshift-service-mesh/prometheus-rhel8@sha256:b0b389a9ee14fbe748a6c5c96f6c4cc1462958f4a923af4de26c8ab4d4defcad_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/ratelimit-rhel8@sha256:fda3a77251f028df047f1e5d433ac7992b613bd824edcf3130cd91b10d7bd1ec_amd64 as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/istio-cni-rhel8@sha256:1e4ec039f046fb633bdea3c2a41b949cd240f205f1d8c54cadaae6038b68a95b_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/istio-cni-rhel8@sha256:1e4ec039f046fb633bdea3c2a41b949cd240f205f1d8c54cadaae6038b68a95b_amd64 |
| Red Hat | openshift-service-mesh/proxyv2-rhel8@sha256:65eec2ccdb679ba214033dfd47e06333045089daf3f13ce5bd997fd542a14afb_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8@sha256:65eec2ccdb679ba214033dfd47e06333045089daf3f13ce5bd997fd542a14afb_ppc64le |
…and 12 more
Timeline
- Jun 6, 2024 CVE Published
- Apr 25, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:3680 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3680.json advisory
- https://access.redhat.com/security/cve/CVE-2023-45288 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-45288 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-45288 advisory
- https://nowotarski.info/http2-continuation-flood/ advisory
- https://pkg.go.dev/vuln/GO-2024-2687 advisory
- https://www.kb.cert.org/vuls/id/421644 advisory