Incomplete Fix for CVE-2023-39325/CVE-2023-44487 in Red Hat OpenStack Platform
CVE-2024-4438
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 8 May 2024
Summary
The etcd package in the Red Hat OpenStack platform is vulnerable due to an incomplete fix related to previous CVEs, specifically CVE-2023-39325 and CVE-2023-44487, commonly referred to as Rapid Reset. This vulnerability arises because the etcd package utilizes the http://golang.org/x/net/http2 source instead of the properly managed version from Red Hat Enterprise Linux. This misconfiguration necessitates an update at compile time to ensure the integrity and security of the Red Hat OpenStack implementation. Organizations using affected versions should consider immediate remediation to mitigate potential security risks.
Affected Version(s)
Red Hat OpenStack Platform 16.1 0:3.3.23-16.el8ost
Red Hat OpenStack Platform 16.2 0:3.3.23-16.el8ost
Red Hat OpenStack Platform 17.1 for RHEL 9 0:3.4.26-8.el9ost
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved