Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Logging Subsystem 5.7.2 - Red Hat OpenShift
Security Fix(es):
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK
decoding (CVE-2022-41723)
* rubygem-rack: denial of service in header parsing (CVE-2023-27539)
* rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
(CVE-2023-28120)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2021-26341 https://access.redhat.com/security/cve/CVE-2021-33655 https://access.redhat.com/security/cve/CVE-2021-33656 https://access.redhat.com/security/cve/CVE-2022-1462 https://access.redhat.com/security/cve/CVE-2022-1679 https://access.redhat.com/security/cve/CVE-2022-1789 https://access.redhat.com/security/cve/CVE-2022-2196 https://access.redhat.com/security/cve/CVE-2022-2663 https://access.redhat.com/security/cve/CVE-2022-3028 https://access.redhat.com/security/cve/CVE-2022-3239 https://access.redhat.com/security/cve/CVE-2022-3522 https://access.redhat.com/security/cve/CVE-2022-3524 https://access.redhat.com/security/cve/CVE-2022-3564 https://access.redhat.com/security/cve/CVE-2022-3566 https://access.redhat.com/security/cve/CVE-2022-3567 https://access.redhat.com/security/cve/CVE-2022-3619 https://access.redhat.com/security/cve/CVE-2022-3623 https://access.redhat.com/security/cve/CVE-2022-3625 https://access.redhat.com/security/cve/CVE-2022-3627 https://access.redhat.com/security/cve/CVE-2022-3628 https://access.redhat.com/security/cve/CVE-2022-3707 https://access.redhat.com/security/cve/CVE-2022-3970 https://access.redhat.com/security/cve/CVE-2022-4129 https://access.redhat.com/security/cve/CVE-2022-20141 Read the Full Advisory
Logging Subsystem 5.7.2 - Red Hat OpenShiftRed Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
2179637 - CVE-2023-28120 rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice
2179649 - CVE-2023-27539 rubygem-rack: denial of service in header parsing
5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):
LOG-3314 - [fluentd] The passphrase can not be enabled when forwarding logs to Kafka
LOG-3316 - openshift-logging namespace can not be deleted directly when use lokistack as default store.
LOG-3330 - run.sh shows incorrect chunk_limit_size if changed.
LOG-3445 - [vector to loki] validation is not disabled when tls.insecureSkipVerify=true
LOG-3749 - Unability to configure nodePlacement and toleration for logging-view-plugin
LOG-3784 - [fluentd http] the defaut value HTTP content type application/x-ndjson is unsupported on datadog
LOG-3827 - [fluentd http] The passphase isn't generated in fluent.conf
LOG-3878 - [vector] PHP multiline errors are collected line by line when detectMultilineErrors is enabled.
LOG-3945 - [Vector] Collector pods in CrashLoopBackOff when ClusterLogForwarder pipeline has space in between the pipeline name.
LOG-3997 - Add http to log_forwarder_output_info metrics
LOG-4011 - [Vector] Collector not complying with the custom tlsSecurityProfile configuration.
Get the latest Linux and open source security news straight to your inbox.