CVE-2023-29400

medium
Published 2023-05-25 · Modified 2023-11-27
CVSS v3
CVSS v2
VIR risk
5.5

Description

Moderate: container-tools:rhel8 security and bug fix update

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-6939.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:6939

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-6938.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2182884

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2182883

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2175721

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:6938

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6473.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6363.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6346.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2163037

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6402.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6474.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2228689

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2222167

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196029

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196027

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2196026

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184484

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184483

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184482

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2184481

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178492

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178488

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2178358

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2174485

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-29400

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-29400.html

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6474

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6473

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6402

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6363

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6346

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:3318

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6939

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6938

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description golang: html/template: improper handling of empty HTML attributes Red Hat statement For Red Hat Enterprise Linux, * Conmon uses go in unit testing, but not functionally in the package. Go is used only in test files, not in the actual code. Thus, conmon is not affected. * The Go templates in Grafana do not contain any javascript. Thus, it is not affected. * Ignition does not make use…

Description

golang: html/template: improper handling of empty HTML attributes

Red Hat statement

For Red Hat Enterprise Linux, * Conmon uses go in unit testing, but not functionally in the package. Go is used only in test files, not in the actual code. Thus, conmon is not affected. * The Go templates in Grafana do not contain any javascript. Thus, it is not affected. * Ignition does not make use of html/template. In OpenShift Container Platform and Red Hat Advanced Cluster Management for Kubernetes (RHACM), the affected containers are behind OAuth authentication. This restricts access to the vulnerable golang html/templates to authenticated users, reducing the impact to low.

CVSS v3: 7.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
CERT-MANAGER-1.10-RHEL-9cert-manager-operator-bundle-container-v1.10.3-4RHSA-2023:43352023-08-08T00:00:00Z
CERT-MANAGER-1.10-RHEL-9cert-manager-operator-container-v1.10.3-2RHSA-2023:43352023-08-08T00:00:00Z
CERT-MANAGER-1.10-RHEL-9jetstack-cert-manager-container-v1.10.2-18RHSA-2023:43352023-08-08T00:00:00Z
Migration Toolkit for Virtualization 2.4migration-toolkit-virtualization/mtv-controller-rhel9:2.4.3-5RHBA-2023:61092023-10-25T00:00:00Z
MTA-6.2-RHEL-9mta/mta-hub-rhel9:6.2.0-16RHSA-2023:46272023-08-14T00:00:00Z
NETWORK-OBSERVABILITY-1.3.0-RHEL-9network-observability/network-observability-rhel9-operator:v1.3.0-53RHSA-2023:39052023-06-28T00:00:00Z
OADP-1.1-RHEL-8oadp/oadp-velero-rhel8:1.1.5-3RHSA-2023:39182023-06-29T00:00:00Z
OSSO-1.1-RHEL-8openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8:v1.1-30RHSA-2023:46572023-08-23T00:00:00Z
Red Hat Ansible Automation Platform 2.3 for RHEL 8openshift-clients-0:4.12.0-202307200611.p0.g49844f7.assembly.stream.el8RHSA-2023:44702023-08-03T00:00:00Z
Red Hat Developer Toolsgo-toolset-1.19-golang-0:1.19.9-1.el7_9RHSA-2023:33232023-05-25T00:00:00Z
Red Hat Enterprise Linux 8go-toolset:rhel8-8080020230517172404.6b4b45d8RHSA-2023:33192023-05-25T00:00:00Z
Red Hat Enterprise Linux 8container-tools:4.0-8090020230828093056.e7857ab1RHSA-2023:69382023-11-14T00:00:00Z
Red Hat Enterprise Linux 8container-tools:rhel8-8090020230825121312.e7857ab1RHSA-2023:69392023-11-14T00:00:00Z
Red Hat Enterprise Linux 9golang-0:1.19.9-2.el9_2RHSA-2023:33182023-05-25T00:00:00Z
Red Hat Enterprise Linux 9toolbox-0:0.0.99.4-6.el9_3RHSA-2023:63462023-11-07T00:00:00Z
Red Hat Enterprise Linux 9skopeo-2:1.13.3-1.el9RHSA-2023:63632023-11-07T00:00:00Z
Red Hat Enterprise Linux 9containernetworking-plugins-1:1.3.0-4.el9RHSA-2023:64022023-11-07T00:00:00Z
Red Hat Enterprise Linux 9buildah-1:1.31.3-1.el9RHSA-2023:64732023-11-07T00:00:00Z
Red Hat Enterprise Linux 9podman-2:4.6.1-5.el9RHSA-2023:64742023-11-07T00:00:00Z
Red Hat Migration Toolkit for Containers 1.7rhmtc/openshift-velero-plugin-rhel8:v1.7.11-3RHSA-2023:42932023-07-27T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/cloud-network-config-controller-rhel8:v4.13.0-202305262054.p0.g71ccef5.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/egress-router-cni-rhel8:v4.13.0-202305270643.p0.g879b72b.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/kubevirt-csi-driver-rhel8:v4.13.0-202305262054.p0.gefa0b94.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/network-tools-rhel8:v4.13.0-202305300541.p0.gb4098c6.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/oc-mirror-plugin-rhel8:v4.13.0-202305262054.p0.g74d3207.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/openshift-route-controller-manager-rhel8:v4.13.0-202305262054.p0.gd7a8e22.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-api-server-rhel8:v4.13.0-202305291355.p0.g8db33db.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-csr-approver-rhel8:v4.13.0-202305291355.p0.g6160d18.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-node-agent-rhel8:v4.13.0-202305262054.p0.ge8de058.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-agent-installer-orchestrator-rhel8:v4.13.0-202305262054.p0.g6160d18.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-cloud-controller-manager-rhel8:v4.13.0-202305262054.p0.gb5200ba.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-cloud-csi-driver-container-rhel8:v4.13.0-202305262054.p0.g68c0ecf.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8:v4.13.0-202305262054.p0.g0f4b92a.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-alibaba-machine-controllers-rhel8:v4.13.0-202305262054.p0.g4c0f96a.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-apiserver-network-proxy-rhel8:v4.13.0-202305262054.p0.g61e198c.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-cloud-controller-manager-rhel8:v4.13.0-202305262054.p0.g946daa0.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-cluster-api-controllers-rhel8:v4.13.0-202305262054.p0.g4251ed3.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-ebs-csi-driver-rhel8:v4.13.0-202305262054.p0.gd8fa531.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-ebs-csi-driver-rhel8-operator:v4.13.0-202305262054.p0.gb6dee5c.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-aws-pod-identity-webhook-rhel8:v4.13.0-202305262054.p0.g4969655.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-cloud-controller-manager-rhel8:v4.13.0-202305262054.p0.g7afcf26.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-cloud-node-manager-rhel8:v4.13.0-202305262054.p0.g7afcf26.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-cluster-api-controllers-rhel8:v4.13.0-202305262054.p0.g9885d4d.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-disk-csi-driver-rhel8:v4.13.0-202305262054.p0.g202e8af.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-disk-csi-driver-rhel8-operator:v4.13.0-202305262054.p0.g67bda47.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-file-csi-driver-operator-rhel8:v4.13.0-202305262054.p0.g994c32c.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-azure-file-csi-driver-rhel8:v4.13.0-202305262054.p0.gfd94a03.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-installer-rhel8:v4.13.0-202305270643.p0.gb332f7a.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-machine-controllers:v4.13.0-202305262054.p0.gd20bc57.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-rhel8-operator:v4.13.0-202305290832.p0.gb771b3b.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-baremetal-runtimecfg-rhel8:v4.13.0-202305262054.p0.gf0c1297.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cli:v4.13.0-202305291355.p0.g1024efc.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cli-artifacts:v4.13.0-202305291355.p0.g1024efc.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cloud-credential-operator:v4.13.0-202305262054.p0.gd3b5ffa.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-api-rhel8:v4.13.0-202305262054.p0.g0142186.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-authentication-operator:v4.13.0-202305262054.p0.ga69e6b7.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-autoscaler:v4.13.0-202305262054.p0.gc58c53b.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-autoscaler-operator:v4.13.0-202305262054.p0.g99a0e2b.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-baremetal-operator-rhel8:v4.13.0-202305262054.p0.gdb28311.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-bootstrap:v4.13.0-202305262054.p0.gee908b6.assembly.streamRHSA-2023:33672023-06-07T00:00:00Z

Package state

ProductPackageState
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel8-operatorUnder investigation
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Pipelinesopenshift-pipelines-clientWill not fix
OpenShift Service Mesh 2openshift-golang-builder-containerNot affected
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/subctl-rhel9Affected
Red Hat AMQ Broker 7amq-broker-rhel8-operator-containerAffected
Red Hat Application Interconnect 1.0skupper-cliAffected
Red Hat Ceph Storage 3golangWill not fix
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Enterprise Linux 8container-tools:3.0/containernetworking-pluginsNot affected
Red Hat Enterprise Linux 8container-tools:3.0/skopeoNot affected
Red Hat Enterprise Linux 8container-tools:3.0/toolboxWill not fix
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 8grafana-pcpNot affected
Red Hat Enterprise Linux 8osbuild-composerWill not fix
Red Hat Enterprise Linux 9conmonNot affected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat Enterprise Linux 9grafana-pcpNot affected
Red Hat Enterprise Linux 9ignitionWill not fix
Red Hat Enterprise Linux 9osbuild-composerWill not fix
Red Hat OpenShift Container Platform 4containernetworking-pluginsNot affected
Red Hat OpenShift Container Platform 4ignitionNot affected
Red Hat OpenShift Container Platform 4openshiftNot affected
Red Hat Openshift Data Foundation 4mcgAffected
Red Hat OpenShift Data Science (RHODS)rhods/odh-mm-rest-proxy-rhel8Affected
Red Hat OpenShift Dev Spacesdevspaces/udi-rhel8Affected
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-agent-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Will not fix
Red Hat OpenShift GitOpsopenshift-gitops-kamAffected
Red Hat Openshift Sandboxed Containersopenshift-sandboxed-containers/osc-rhel9-operatorUnder investigation
Red Hat OpenShift Virtualization 4kubevirtAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/osp-director-agentNot affected
Red Hat Quay 3quay/clair-rhel8Affected
Red Hat Satellite 6yggdrasil-worker-forwarderNot affected
Red Hat Storage 3golangWill not fix
Red Hat Storage 3go-toolset-7-golangWill not fix
Red Hat Web Terminalweb-terminal-exec-containerAffected
Self Node Remediation Operatorworkload-availability/self-node-remediation-rhel8-operatorAffected

Apply commands

bash fix
Apply RHSA-2023:4335 for CERT-MANAGER-1.10-RHEL-9
yum update -y cert-manager-operator-bundle-container-v1
# or:
dnf upgrade -y cert-manager-operator-bundle-container-v1

Affected

VendorProductVersion
redhatCustom Metric Autoscaler operator for Red Hat OpenshiftNot affected
redhatLogging Subsystem for Red Hat OpenShiftNot affected
redhatOpenShift Developer Tools and ServicesAffected
redhatOpenShift Service Mesh 2Not affected
redhatRed Hat 3scale API Management Platform 2Affected
redhatRed Hat Advanced Cluster Management for Kubernetes 2Affected
redhatRed Hat AMQ Broker 7Affected
redhatRed Hat Application Interconnect 1.0Affected
redhatRed Hat Ceph Storage 5Affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat Openshift Data Foundation 4Affected
redhatRed Hat OpenShift Data Science (RHODS)Affected
redhatRed Hat OpenShift Dev SpacesAffected
redhatRed Hat OpenShift distributed tracing 2Affected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat OpenShift Virtualization 4Affected
redhatRed Hat OpenStack Platform 16.2Not affected
redhatRed Hat Quay 3Affected
redhatRed Hat Satellite 6Not affected
redhatRed Hat Web TerminalAffected
redhatSelf Node Remediation OperatorAffected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
redhat rhel9fixed
suse slesaffected
debian debianbullseyeaffected
debian debianbookwormaffected

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.20.0-0,<1.20.41.19.9

References

Verify integrity in audit chain (admin only). AS-IS.