Incomplete Fix for CVE-2023-39325/CVE-2023-44487 in Red Hat OpenStack Platform
CVE-2024-4438

7.5HIGH

Summary

The etcd package in the Red Hat OpenStack platform is vulnerable due to an incomplete fix related to previous CVEs, specifically CVE-2023-39325 and CVE-2023-44487, commonly referred to as Rapid Reset. This vulnerability arises because the etcd package utilizes the http://golang.org/x/net/http2 source instead of the properly managed version from Red Hat Enterprise Linux. This misconfiguration necessitates an update at compile time to ensure the integrity and security of the Red Hat OpenStack implementation. Organizations using affected versions should consider immediate remediation to mitigate potential security risks.

Affected Version(s)

Red Hat OpenStack Platform 16.1 0:3.3.23-16.el8ost

Red Hat OpenStack Platform 16.2 0:3.3.23-16.el8ost

Red Hat OpenStack Platform 17.1 for RHEL 9 0:3.4.26-8.el9ost

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.