CVE-2023-44487
Description
Important: nodejs:20 security update
CISA KEV
- Vendor
- IETF
- Product
- HTTP/2
- Due date
- 2023-10-31
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-7205.html
Vendor advisory: alma — https://bugzilla.redhat.com/2244414
Vendor advisory: alma — https://bugzilla.redhat.com/2244413
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:7205
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5849.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5738.html
Vendor advisory: alma — https://bugzilla.redhat.com/2228743
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5869.html
Vendor advisory: alma — https://bugzilla.redhat.com/2244418
Vendor advisory: alma — https://bugzilla.redhat.com/2244415
Vendor advisory: alma — https://bugzilla.redhat.com/2244104
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5869
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6077.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5867.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5863.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5863
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5721.html
Vendor advisory: alma — https://bugzilla.redhat.com/2243296
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5721
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6746.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5838.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5749.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5708.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5924.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5929.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-6120.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5765.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2023-5711.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5989.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5989
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5710.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5710
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5709.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5709
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-1444.html
Vendor advisory: alma — https://bugzilla.redhat.com/2264574
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:1444
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5928.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5928
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5712.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5712
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5713.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5713
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5850.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5850
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2023-5837.html
Vendor advisory: alma — https://bugzilla.redhat.com/2242803
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2023:5837
Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5924
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5765
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5838
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5749
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5708
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5738
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6120
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6077
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6746
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5849
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-44487.html
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5863
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5928
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5721
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5989
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5850
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:6818
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:7205
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-44487
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:1444
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:3121
Vendor advisory: cve@mitre.org — https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/
Vendor advisory: cve@mitre.org — https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/
Vendor advisory: cve@mitre.org — https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487
Vendor advisory: cve@mitre.org — https://www.debian.org/security/2023/dsa-5522
Vendor advisory: cve@mitre.org — https://www.debian.org/security/2023/dsa-5521
Vendor advisory: cve@mitre.org — https://ubuntu.com/security/CVE-2023-44487
Vendor advisory: cve@mitre.org — https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14
Vendor advisory: cve@mitre.org — https://security.paloaltonetworks.com/CVE-2023-44487
Vendor advisory: cve@mitre.org — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ
Vendor advisory: cve@mitre.org — https://netty.io/news/2023/10/10/4-1-100-Final.html
Vendor advisory: cve@mitre.org — https://my.f5.com/manage/s/article/K000137106
Vendor advisory: cve@mitre.org — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487
Vendor advisory: cve@mitre.org — https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/
Vendor advisory: cve@mitre.org — https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
Vendor advisory: cve@mitre.org — https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/
Vendor advisory: cve@mitre.org — https://istio.io/latest/news/security/istio-security-2023-004/
Vendor advisory: cve@mitre.org — https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
Vendor advisory: cve@mitre.org — https://github.com/projectcontour/contour/pull/5826
Vendor advisory: cve@mitre.org — https://github.com/opensearch-project/data-prepper/issues/3474
Vendor advisory: cve@mitre.org — https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
Vendor advisory: cve@mitre.org — https://github.com/nghttp2/nghttp2/pull/1961
Vendor advisory: cve@mitre.org — https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61
Vendor advisory: cve@mitre.org — https://github.com/microsoft/CBL-Mariner/pull/6381
Vendor advisory: cve@mitre.org — https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632
Vendor advisory: cve@mitre.org — https://github.com/line/armeria/pull/5232
Vendor advisory: cve@mitre.org — https://github.com/kubernetes/kubernetes/pull/121120
Vendor advisory: cve@mitre.org — https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1
Vendor advisory: cve@mitre.org — https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf
Vendor advisory: cve@mitre.org — https://github.com/h2o/h2o/pull/3291
Vendor advisory: cve@mitre.org — https://github.com/grpc/grpc-go/pull/6703
Vendor advisory: cve@mitre.org — https://github.com/facebook/proxygen/pull/466
Vendor advisory: cve@mitre.org — https://github.com/etcd-io/etcd/issues/16740
Vendor advisory: cve@mitre.org — https://github.com/envoyproxy/envoy/pull/30055
Vendor advisory: cve@mitre.org — https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73
Vendor advisory: cve@mitre.org — https://github.com/dotnet/announcements/issues/277
Vendor advisory: cve@mitre.org — https://github.com/caddyserver/caddy/releases/tag/v2.7.5
Vendor advisory: cve@mitre.org — https://github.com/caddyserver/caddy/issues/5877
Vendor advisory: cve@mitre.org — https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487
Vendor advisory: cve@mitre.org — https://github.com/apache/trafficserver/pull/10564
Vendor advisory: cve@mitre.org — https://github.com/advisories/GHSA-xpw8-rcwv-8f8p
Vendor advisory: cve@mitre.org — https://github.com/advisories/GHSA-vx74-f528-fxqg
Vendor advisory: cve@mitre.org — https://github.com/advisories/GHSA-qppj-fm5r-hxr3
Vendor advisory: cve@mitre.org — https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
Vendor advisory: cve@mitre.org — https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764
Vendor advisory: cve@mitre.org — https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125
Vendor advisory: cve@mitre.org — https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack
Vendor advisory: cve@mitre.org — https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Vendor advisory: cve@mitre.org — https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9
Vendor advisory: cve@mitre.org — https://bugzilla.suse.com/show_bug.cgi?id=1216123
Vendor advisory: cve@mitre.org — https://bugzilla.redhat.com/show_bug.cgi?id=2242803
Vendor advisory: cve@mitre.org — https://blog.vespa.ai/cve-2023-44487/
Vendor advisory: cve@mitre.org — https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/
Vendor advisory: cve@mitre.org — https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
Vendor advisory: cve@mitre.org — https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
Vendor advisory: cve@mitre.org — https://access.redhat.com/security/cve/cve-2023-44487
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:2368
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6746
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6120
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:6077
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5929
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5924
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5867
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5849
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5838
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5765
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5749
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5738
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5711
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2023:5708
Vendor advisory: redhat — https://access.redhat.com/errata/RHEA-2023:6741
Vendor advisory: redhat — https://access.redhat.com/errata/RHEA-2023:6562
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5869
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2023:5837
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rocky | 8 | fixed | |
| rhel | 9 | fixed | |
| debian | forky | fixed | 1.8.2-2 |
| debian | sid | fixed | 1.8.2-2 |
| debian | trixie | fixed | 1.8.2-2 |
| sles | affected | | |
| debian | bookworm | fixed | 1.8.13-1 |
| debian | bullseye | fixed | 1.8.13-1 |
| rocky | 9 | fixed | |
| debian | 10.0 | affected | |
| debian | 11.0 | affected | |
| debian | 12.0 | affected | |
| fedora | 37 | affected | |
| fedora | 38 | affected | |
| windows | - | affected | |
| rhel | 6.0 | affected | |
| rhel | 8.0 | affected | |
| rhel | 9.0 | affected | |
Package impact
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| siemens | sinec_ins | {"endExcluding":"1.0"} | 1.0 |
| siemens | sinec_ins | 1.0 | |
| siemens | sinec_nms | {"endExcluding":"3.0"} | 3.0 |
| siemens | st7_scadaconnect | {"endExcluding":"1.1"} | 1.1 |
| ietf | http | 2.0 | |
| nghttp2 | nghttp2 | {"endExcluding":"1.57.0"} | 1.57.0 |
| netty | netty | {"endExcluding":"4.1.100"} | 4.1.100 |
| envoyproxy | envoy | 1.24.10 | |
| envoyproxy | envoy | 1.25.9 | |
| envoyproxy | envoy | 1.26.4 | |
| envoyproxy | envoy | 1.27.0 | |
| eclipse | jetty | {"endExcluding":"9.4.53"} | 9.4.53 |
| caddyserver | caddy | {"endExcluding":"2.7.5"} | 2.7.5 |
| golang | go | {"endExcluding":"1.20.10"} | 1.20.10 |
| golang | http2 | {"endExcluding":"0.17.0"} | 0.17.0 |
| golang | networking | {"endExcluding":"0.17.0"} | 0.17.0 |
| f5 | big-ip_access_policy_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_access_policy_manager | 17.1.0 | |
| f5 | big-ip_advanced_firewall_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 | |
| f5 | big-ip_advanced_web_application_firewall | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 | |
| f5 | big-ip_analytics | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_analytics | 17.1.0 | |
| f5 | big-ip_application_acceleration_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_application_acceleration_manager | 17.1.0 | |
| f5 | big-ip_application_security_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_application_security_manager | 17.1.0 | |
| f5 | big-ip_application_visibility_and_reporting | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_application_visibility_and_reporting | 17.1.0 | |
| f5 | big-ip_carrier-grade_nat | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_carrier-grade_nat | 17.1.0 | |
| f5 | big-ip_ddos_hybrid_defender | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_ddos_hybrid_defender | 17.1.0 | |
| f5 | big-ip_domain_name_system | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_domain_name_system | 17.1.0 | |
| f5 | big-ip_fraud_protection_service | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_fraud_protection_service | 17.1.0 | |
| f5 | big-ip_global_traffic_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_global_traffic_manager | 17.1.0 | |
| f5 | big-ip_link_controller | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_link_controller | 17.1.0 | |
| f5 | big-ip_local_traffic_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_local_traffic_manager | 17.1.0 | |
| f5 | big-ip_next | 20.0.1 | |
| f5 | big-ip_next_service_proxy_for_kubernetes | {"startIncluding":"1.5.0","endIncluding":"1.8.2"} | |
| f5 | big-ip_policy_enforcement_manager | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_policy_enforcement_manager | 17.1.0 | |
| f5 | big-ip_ssl_orchestrator | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_ssl_orchestrator | 17.1.0 | |
| f5 | big-ip_webaccelerator | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_webaccelerator | 17.1.0 | |
| f5 | big-ip_websafe | {"startIncluding":"13.1.0","endIncluding":"13.1.5"} | |
| f5 | big-ip_websafe | 17.1.0 | |
| f5 | nginx | {"startIncluding":"1.9.5","endIncluding":"1.25.2"} | |
| f5 | nginx_ingress_controller | {"startIncluding":"2.0.0","endIncluding":"2.4.2"} | |
| f5 | nginx_plus | {"startIncluding":"r25","endExcluding":"r29"} | r29 |
| f5 | nginx_plus | r29 | |
| f5 | nginx_plus | r30 | |
| apache | tomcat | {"startIncluding":"8.5.0","endIncluding":"8.5.93"} | |
| apache | tomcat | 11.0.0 | |
| apple | swiftnio_http\/2 | {"endExcluding":"1.28.0"} | 1.28.0 |
| grpc | grpc | {"endExcluding":"1.56.3"} | 1.56.3 |
| grpc | grpc | 1.57.0 | |
| microsoft | .net | {"startIncluding":"6.0.0","endExcluding":"6.0.23"} | 6.0.23 |
| microsoft | asp.net_core | {"startIncluding":"6.0.0","endExcluding":"6.0.23"} | 6.0.23 |
| microsoft | azure_kubernetes_service | {"endExcluding":"2023-10-08"} | 2023-10-08 |
| microsoft | visual_studio_2022 | {"startIncluding":"17.0","endExcluding":"17.2.20"} | 17.2.20 |
| nodejs | node.js | {"startIncluding":"18.0.0","endExcluding":"18.18.2"} | 18.18.2 |
| microsoft | cbl-mariner | {"endExcluding":"2023-10-11"} | 2023-10-11 |
| dena | h2o | {"endExcluding":"2023-10-10"} | 2023-10-10 |
| proxygen | {"endExcluding":"2023.10.16.00"} | 2023.10.16.00 | |
| apache | apisix | {"endExcluding":"3.6.1"} | 3.6.1 |
| apache | traffic_server | {"startIncluding":"8.0.0","endExcluding":"8.1.9"} | 8.1.9 |
| amazon | opensearch_data_prepper | {"endExcluding":"2.5.0"} | 2.5.0 |
| kazu-yamamoto | http2 | {"endExcluding":"4.2.2"} | 4.2.2 |
| istio | istio | {"endExcluding":"1.17.6"} | 1.17.6 |
| varnish_cache_project | varnish_cache | {"endExcluding":"2023-10-10"} | 2023-10-10 |
| traefik | traefik | {"endExcluding":"2.10.5"} | 2.10.5 |
| traefik | traefik | 3.0.0 | |
| projectcontour | contour | {"endExcluding":"2023-10-11"} | 2023-10-11 |
| linkerd | linkerd | {"startIncluding":"2.12.0","endIncluding":"2.12.5"} | |
| linkerd | linkerd | 2.13.0 | |
| linkerd | linkerd | 2.13.1 | |
| linkerd | linkerd | 2.14.0 | |
| linkerd | linkerd | 2.14.1 | |
| linecorp | armeria | {"endExcluding":"1.26.0"} | 1.26.0 |
| redhat | 3scale_api_management_platform | 2.0 | |
| redhat | advanced_cluster_management_for_kubernetes | 2.0 | |
| redhat | advanced_cluster_security | 3.0 | |
| redhat | advanced_cluster_security | 4.0 | |
| redhat | ansible_automation_platform | 2.0 | |
| redhat | build_of_optaplanner | 8.0 | |
| redhat | build_of_quarkus | - | |
| redhat | ceph_storage | 5.0 | |
| redhat | cert-manager_operator_for_red_hat_openshift | - | |
| redhat | certification_for_red_hat_enterprise_linux | 8.0 | |
| redhat | certification_for_red_hat_enterprise_linux | 9.0 | |
| redhat | cost_management | - | |
| redhat | cryostat | 2.0 | |
| redhat | decision_manager | 7.0 | |
| redhat | fence_agents_remediation_operator | - | |
| redhat | integration_camel_for_spring_boot | - | |
| redhat | integration_camel_k | - | |
| redhat | integration_service_registry | - | |
| redhat | jboss_a-mq | 7 | |
| redhat | jboss_a-mq_streams | - | |
| redhat | jboss_core_services | - | |
| redhat | jboss_data_grid | 7.0.0 | |
| redhat | jboss_enterprise_application_platform | 6.0.0 | |
| redhat | jboss_enterprise_application_platform | 7.0.0 | |
| redhat | jboss_fuse | 6.0.0 | |
| redhat | jboss_fuse | 7.0.0 | |
| redhat | logging_subsystem_for_red_hat_openshift | - | |
| redhat | machine_deletion_remediation_operator | - | |
| redhat | migration_toolkit_for_applications | 6.0 | |
| redhat | migration_toolkit_for_containers | - | |
| redhat | migration_toolkit_for_virtualization | - | |
| redhat | network_observability_operator | - | |
| redhat | node_healthcheck_operator | - | |
| redhat | node_maintenance_operator | - | |
| redhat | openshift | - | |
| redhat | openshift_api_for_data_protection | - | |
| redhat | openshift_container_platform | 4.0 | |
| redhat | openshift_container_platform_assisted_installer | - | |
| redhat | openshift_data_science | - | |
| redhat | openshift_dev_spaces | - | |
| redhat | openshift_developer_tools_and_services | - | |
| redhat | openshift_distributed_tracing | - | |
| redhat | openshift_gitops | - | |
| redhat | openshift_pipelines | - | |
| redhat | openshift_sandboxed_containers | - | |
| redhat | openshift_secondary_scheduler_operator | - | |
| redhat | openshift_serverless | - | |
| redhat | openshift_service_mesh | 2.0 | |
| redhat | openshift_virtualization | 4 | |
| redhat | openstack_platform | 16.1 | |
| redhat | openstack_platform | 16.2 | |
| redhat | openstack_platform | 17.1 | |
| redhat | process_automation | 7.0 | |
| redhat | quay | 3.0.0 | |
| redhat | run_once_duration_override_operator | - | |
| redhat | satellite | 6.0 | |
| redhat | self_node_remediation_operator | - | |
| redhat | service_interconnect | 1.0 | |
| redhat | single_sign-on | 7.0 | |
| redhat | support_for_spring_boot | - | |
| redhat | web_terminal | - | |
| redhat | service_telemetry_framework | 1.5 | |
| netapp | astra_control_center | - | |
| netapp | oncommand_insight | - | |
| akka | http_server | {"endExcluding":"10.5.3"} | 10.5.3 |
| konghq | kong_gateway | {"endExcluding":"3.4.2"} | 3.4.2 |
| jenkins | jenkins | {"endIncluding":"2.414.2"} | |
| apache | solr | {"endExcluding":"9.4.0"} | 9.4.0 |
| openresty | openresty | {"endExcluding":"1.21.4.3"} | 1.21.4.3 |
| cisco | business_process_automation | {"endExcluding":"3.2.003.009"} | 3.2.003.009 |
| cisco | connected_mobile_experiences | {"endExcluding":"11.1"} | 11.1 |
| cisco | crosswork_data_gateway | {"endExcluding":"4.1.3"} | 4.1.3 |
| cisco | crosswork_situation_manager | - | |
| cisco | crosswork_zero_touch_provisioning | {"endExcluding":"6.0.0"} | 6.0.0 |
| cisco | data_center_network_manager | - | |
| cisco | enterprise_chat_and_email | - | |
| cisco | expressway | {"endExcluding":"x14.3.3"} | x14.3.3 |
| cisco | firepower_threat_defense | {"endExcluding":"7.4.2"} | 7.4.2 |
| cisco | iot_field_network_director | {"endExcluding":"4.11.0"} | 4.11.0 |
| cisco | prime_access_registrar | {"endExcluding":"9.3.3"} | 9.3.3 |
| cisco | prime_cable_provisioning | {"endExcluding":"7.2.1"} | 7.2.1 |
| cisco | prime_infrastructure | {"endExcluding":"3.10.4"} | 3.10.4 |
| cisco | prime_network_registrar | {"endExcluding":"11.2"} | 11.2 |
| cisco | secure_dynamic_attributes_connector | {"endExcluding":"2.2.0"} | 2.2.0 |
| cisco | secure_malware_analytics | {"endExcluding":"2.19.2"} | 2.19.2 |
| cisco | telepresence_video_communication_server | {"endExcluding":"x14.3.3"} | x14.3.3 |
| cisco | ultra_cloud_core_-_policy_control_function | {"endExcluding":"2024.01.0"} | 2024.01.0 |
| cisco | ultra_cloud_core_-_policy_control_function | 2024.01.0 | |
| cisco | ultra_cloud_core_-_serving_gateway_function | {"endExcluding":"2024.02.0"} | 2024.02.0 |
| cisco | ultra_cloud_core_-_session_management_function | {"endExcluding":"2024.02.0"} | 2024.02.0 |
| cisco | unified_attendant_console_advanced | - | |
| cisco | unified_contact_center_domain_manager | - | |
| cisco | unified_contact_center_enterprise | - | |
| cisco | unified_contact_center_enterprise_-_live_data_server | {"endExcluding":"12.6.2"} | 12.6.2 |
| cisco | unified_contact_center_management_portal | - | |
References
- https://errata.rockylinux.org/RLSA-2023:5837
- https://errata.rockylinux.org/RLSA-2023:5869
- https://access.redhat.com/errata/RHEA-2023:6562
- https://access.redhat.com/errata/RHEA-2023:6741
- https://access.redhat.com/errata/RHSA-2023:5708
- https://access.redhat.com/errata/RHSA-2023:5711
- https://access.redhat.com/errata/RHSA-2023:5738
- https://access.redhat.com/errata/RHSA-2023:5749
- https://access.redhat.com/errata/RHSA-2023:5765
- https://access.redhat.com/errata/RHSA-2023:5838
- https://access.redhat.com/errata/RHSA-2023:5849
- https://access.redhat.com/errata/RHSA-2023:5867
- https://access.redhat.com/errata/RHSA-2023:5924
- https://access.redhat.com/errata/RHSA-2023:5929
- https://access.redhat.com/errata/RHSA-2023:6077
- https://access.redhat.com/errata/RHSA-2023:6120
- https://access.redhat.com/errata/RHSA-2023:6746
- https://access.redhat.com/errata/RHSA-2024:2368
- http://www.openwall.com/lists/oss-security/2023/10/10/6
- http://www.openwall.com/lists/oss-security/2023/10/10/7
- http://www.openwall.com/lists/oss-security/2023/10/13/4
- http://www.openwall.com/lists/oss-security/2023/10/13/9
- http://www.openwall.com/lists/oss-security/2023/10/18/4
- http://www.openwall.com/lists/oss-security/2023/10/18/8
- http://www.openwall.com/lists/oss-security/2023/10/19/6
CWEs
CWE-400
Verify integrity in audit chain (admin only). AS-IS.