Resource exhaustion in otelhttp - CVE-2023-45142

 

Resource exhaustion in otelhttp - CVE-2023-45142

Published: November 29, 2023


Vulnerability identifier: #VU83546
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-45142
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect processing of HTTP header User-Agent and HTTP method. A remote attacker can send multiple requests with long randomly generated HTTP methods or/and User agents and consume memory resources, leading to a denial of service condition.

Affected software

otelhttp
PowerStore 9200T
PowerStore 500T
PowerStore 1000T
PowerStore 5000T
PowerStore 5200T
PowerStore 7000T
PowerStore 3200T
PowerStore 3000T
PowerStore 1200T
PowerStore 9000T
PowerStoreT OS
IBM Cloud Pak for Data Scheduling
Red Hat Advanced Cluster Management for Kubernetes
Netcool Operations Insight
IBM MQ Operator
Red Hat OpenShift distributed tracing (RHOSDT)
APEX Cloud Platform for Red Hat OpenShift
Ceph
IBM Robotic Process Automation
Amazon Linux AMI
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy Module
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE Manager Client Tools for SLE
Containers Module
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Package Hub 15
openSUSE Leap
Fedora
OpenShift API for Data Protection (OADP)
Caddy
Guardium Data Security Center (GDSC)
ObjectScale
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
IBM supplied MQ Advanced container images
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
Dell EMC VxRail Appliance
RSA Authentication Manager
Splunk Enterprise
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
mgrctl-debuginfo
mgrctl
mgrctl-bash-completion
mgrctl-zsh-completion
mgrctl-lang
firewalld-prometheus-config
containerd
containerd-devel
containerd-ctr
amazon-cloudwatch-agent
caddy
golang-github-prometheus-prometheus
python2-rhnlib
python3-rhnlib
spacecmd
ceph-ansible (Red Hat package)
docker-bash-completion
docker-debuginfo
docker
docker-zsh-completion
docker-fish-completion
docker-rootless-extras
Red Hat Ceph Storage

How to mitigate CVE-2023-45142

Install updates from vendor's website.

otelhttp - update to 0.44.0
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.0, 1.3.1
Caddy - update to 2.7.6
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.3, 2.10.5
Guardium Data Security Center (GDSC) - update to 3.7.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.50, 4.13.32, 4.13.51, 4.14.4, 4.14.5, 4.14.6, 4.14.7, 4.14.8, 4.14.9, 4.14.11, 4.14.35, 4.14.36, 4.15.0, 4.15.13, 4.15.38, 4.16.0, 4.17.1
Dell EMC VxRail Appliance - addressed in versions 7.0.540, 8.0.311, 8.321
RSA Authentication Manager - addressed in versions 8.7 SP2 Patch 5, 8.7 SP2 Patch 6
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
mgrctl-debuginfo - addressed in versions 0.1.21-1.8.1, 0.1.21-150000.1.8.2
mgrctl - addressed in versions 0.1.21-1.8.1, 0.1.21-150000.1.8.2
mgrctl-bash-completion - addressed in versions 0.1.21-1.8.1, 0.1.21-150000.1.8.2
mgrctl-zsh-completion - addressed in versions 0.1.21-1.8.1, 0.1.21-150000.1.8.2
mgrctl-lang - update to 0.1.21-150000.1.8.2
firewalld-prometheus-config - addressed in versions 0.1-150000.3.56.1, 0.1-150100.4.20.1
ObjectScale - update to 1.4.0
Netcool Operations Insight - update to 1.6.12
containerd - addressed in versions 1.7.21-16.94.1, 1.7.21-150000.117.1
containerd-devel - update to 1.7.21-150000.117.1
containerd-ctr - update to 1.7.21-150000.117.1
amazon-cloudwatch-agent - update to 1.300032.3-1
IBM MQ Operator - addressed in versions 2.0.18, 2.4.7, 3.0.1
caddy - addressed in versions 2.7.6-1.fc39, 2.7.6-1.fc40
golang-github-prometheus-prometheus - addressed in versions 2.45.6-1.53.1, 2.45.6-150000.3.56.1, 2.45.6-150100.4.20.1
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.0.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
PowerStoreT OS - update to 3.6.1.5-2456810
IBM Cloud Pak for Watson AIOps - update to 4.4.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
python2-rhnlib - update to 5.0.4-21.52.1
python3-rhnlib - update to 5.0.4-150000.3.46.1
spacecmd - addressed in versions 5.0.9-38.147.1, 5.0.9-150000.3.124.1
Red Hat Ceph Storage - update to 5.3
ceph-ansible (Red Hat package) - update to 6.0.28.8-1.el8cp
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.15-r1, 9.3.3.3-r1, 9.3.4.1-r1
Ceph - addressed in versions 16.2.10-266.el8cp, 16.2.10-266.el9cp
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
docker-bash-completion - addressed in versions 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1
docker-debuginfo - addressed in versions 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1
docker - addressed in versions 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1
docker-zsh-completion - update to 26.1.5_ce-150000.212.1
docker-fish-completion - update to 26.1.5_ce-150000.212.1
docker-rootless-extras - update to 26.1.5_ce-150000.212.1

External References

Related Security Bulletins