Observable discrepancy in Go programming language - CVE-2023-45287
Published: February 9, 2024
Vulnerability identifier: #VU86309
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-45287
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a timing discrepancy when handling RSA based TLS key exchanges. A remote attacker can perform a Marvin attack and gain access to sensitive information.
Affected software
Go programming language
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Service Interconnect
Service Telemetry Framework
Operations Dashboard
IBM Concert Software
Run Once Duration Override Operator for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
ObjectScale
IBM Cloud Pak for Watson AIOps
Storage Protect Server
Storage Protect Plus Server
Red Hat OpenShift Container Platform
Fedora
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
toolbox
toolbox-tests
toolbox (Red Hat package)
collectd-sensubility (Red Hat package)
udica
rust-bootupd (Red Hat package)
coreos-installer (Red Hat package)
containernetworking-plugins
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
crun
aardvark-dns
netavark
skopeo (Red Hat package)
fuse-overlayfs
crun (Red Hat package)
skopeo-tests
skopeo
golang
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah
buildah-tests
containers-common
conmon (Red Hat package)
conmon
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
etcd (Red Hat package)
criu
crit
criu-devel
criu-libs
python3-criu
podman-gvproxy
podman-docker
podman-plugins
podman-remote
podman-tests
podman-catatonit
podman
libslirp
libslirp-devel
podman (Red Hat package)
python3-podman
ose-aws-ecr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
microshift (Red Hat package)
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
cockpit-podman
ostree (Red Hat package)
rpm-ostree (Red Hat package)
IBM Security Verify Access
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Service Interconnect
Service Telemetry Framework
Operations Dashboard
IBM Concert Software
Run Once Duration Override Operator for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
ObjectScale
IBM Cloud Pak for Watson AIOps
Storage Protect Server
Storage Protect Plus Server
Red Hat OpenShift Container Platform
Fedora
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
toolbox
toolbox-tests
toolbox (Red Hat package)
collectd-sensubility (Red Hat package)
udica
rust-bootupd (Red Hat package)
coreos-installer (Red Hat package)
containernetworking-plugins
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins (Red Hat package)
crun
aardvark-dns
netavark
skopeo (Red Hat package)
fuse-overlayfs
crun (Red Hat package)
skopeo-tests
skopeo
golang
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
buildah
buildah-tests
containers-common
conmon (Red Hat package)
conmon
ignition (Red Hat package)
container-selinux (Red Hat package)
container-selinux
etcd (Red Hat package)
criu
crit
criu-devel
criu-libs
python3-criu
podman-gvproxy
podman-docker
podman-plugins
podman-remote
podman-tests
podman-catatonit
podman
libslirp
libslirp-devel
podman (Red Hat package)
python3-podman
ose-aws-ecr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
microshift (Red Hat package)
rust-afterburn (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
cockpit-podman
ostree (Red Hat package)
rpm-ostree (Red Hat package)
IBM Security Verify Access
How to mitigate CVE-2023-45287
Install updates from vendor's website.
Go programming language - update to 1.20
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.14, 4.14.33, 4.15.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.1.2-1.rhaos4.15.el9
collectd-sensubility (Red Hat package) - addressed in versions 0.2.1-3.el8ost, 0.2.1-3.el9ost
udica - update to 0.2.6-21
rust-bootupd (Red Hat package) - update to 0.2.17-1.el9
coreos-installer (Red Hat package) - update to 0.17.0-3.rhaos4.15.el9
IBM Concert Software - update to 1.0.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.1.0
containernetworking-plugins - addressed in versions 1.1.1-6.0.1, 1.4.0-2.0.1
runc (Red Hat package) - addressed in versions 1.1.12-1.rhaos4.15.el9, 1.1.12-2.el9
runc - update to 1.1.12-1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - addressed in versions 1.2.5-2.0.1, 1.2.10-1
ObjectScale - update to 1.4.0
containernetworking-plugins (Red Hat package) - update to 1.4.0-2.el9_4
crun - addressed in versions 1.8.7-1.0.1, 1.14.3-2
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
skopeo (Red Hat package) - addressed in versions 1.11.2-21.1.rhaos4.15.el9, 1.14.3-0.1.el9
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14-1.rhaos4.15.el9
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - update to 1.20.12-1.el7
cri-tools (Red Hat package) - update to 1.28.0-3.el9
cri-o (Red Hat package) - update to 1.28.3-14.rhaos4.15.git33aabd8.el9
buildah (Red Hat package) - addressed in versions 1.29.1-20.2.rhaos4.15.el9, 1.33.6-2.el9
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
conmon (Red Hat package) - update to 2.1.7-1.2.rhaos4.14.el9
conmon - update to 2.1.10-1
ignition (Red Hat package) - update to 2.16.2-2.rhaos4.15.el9
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.15.el9
container-selinux - update to 2.229.0-2
etcd (Red Hat package) - update to 3.4.26-8.el9ost
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman-gvproxy - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-docker - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-plugins - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-remote - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-tests - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-catatonit - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-21.rhaos4.15.el9, 4.9.4-0.1.el9
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
ose-aws-ecr-image-credential-provider (Red Hat package) - update to 4.15.0-202401231232.p0.gba252ab.assembly.stream.el9
openshift-clients (Red Hat package) - update to 4.15.0-202402070507.p0.g48dcf59.assembly.stream.el9
openshift (Red Hat package) - update to 4.15.0-202402142009.p0.g6216ea1.assembly.stream.el9
openshift-ansible (Red Hat package) - update to 4.15.0-202402162207.p0.g1c9b99e.assembly.stream.el9
microshift (Red Hat package) - update to 4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
rust-afterburn (Red Hat package) - update to 5.4.3-2.rhaos4.15.el9
kernel (Red Hat package) - update to 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.54.1.rt14.339.el9_2
Red Hat Migration Toolkit for Applications - update to 7.0.3
Storage Protect Server - update to 8.1.23
IBM Security Verify Access - update to 10.0.9
Storage Protect Plus Server - update to 10.1.16.2
Red Hat OpenStack - update to 17.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
cockpit-podman - addressed in versions 46-1, 84.1-1
ostree (Red Hat package) - update to 2023.8-3.el9
rpm-ostree (Red Hat package) - update to 2024.2-1.el9
OpenShift API for Data Protection (OADP) - update to 1.3.1
Service Interconnect - update to 1.5.3
Service Telemetry Framework - update to 1.5.4
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Red Hat OpenShift Container Platform - addressed in versions 4.13.45, 4.14.14, 4.14.33, 4.15.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.1.2-1.rhaos4.15.el9
collectd-sensubility (Red Hat package) - addressed in versions 0.2.1-3.el8ost, 0.2.1-3.el9ost
udica - update to 0.2.6-21
rust-bootupd (Red Hat package) - update to 0.2.17-1.el9
coreos-installer (Red Hat package) - update to 0.17.0-3.rhaos4.15.el9
IBM Concert Software - update to 1.0.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.1.0
containernetworking-plugins - addressed in versions 1.1.1-6.0.1, 1.4.0-2.0.1
runc (Red Hat package) - addressed in versions 1.1.12-1.rhaos4.15.el9, 1.1.12-2.el9
runc - update to 1.1.12-1.0.1
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.2.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - addressed in versions 1.2.5-2.0.1, 1.2.10-1
ObjectScale - update to 1.4.0
containernetworking-plugins (Red Hat package) - update to 1.4.0-2.el9_4
crun - addressed in versions 1.8.7-1.0.1, 1.14.3-2
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
skopeo (Red Hat package) - addressed in versions 1.11.2-21.1.rhaos4.15.el9, 1.14.3-0.1.el9
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14-1.rhaos4.15.el9
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
golang - update to 1.20.12-1.el7
cri-tools (Red Hat package) - update to 1.28.0-3.el9
cri-o (Red Hat package) - update to 1.28.3-14.rhaos4.15.git33aabd8.el9
buildah (Red Hat package) - addressed in versions 1.29.1-20.2.rhaos4.15.el9, 1.33.6-2.el9
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
conmon (Red Hat package) - update to 2.1.7-1.2.rhaos4.14.el9
conmon - update to 2.1.10-1
ignition (Red Hat package) - update to 2.16.2-2.rhaos4.15.el9
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.15.el9
container-selinux - update to 2.229.0-2
etcd (Red Hat package) - update to 3.4.26-8.el9ost
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman-gvproxy - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-docker - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-plugins - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-remote - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-tests - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman-catatonit - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
podman - addressed in versions 4.0.2-26.0.1, 4.9.4-1.0.1
IBM Cloud Pak for Watson AIOps - update to 4.4.0
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-21.rhaos4.15.el9, 4.9.4-0.1.el9
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
ose-aws-ecr-image-credential-provider (Red Hat package) - update to 4.15.0-202401231232.p0.gba252ab.assembly.stream.el9
openshift-clients (Red Hat package) - update to 4.15.0-202402070507.p0.g48dcf59.assembly.stream.el9
openshift (Red Hat package) - update to 4.15.0-202402142009.p0.g6216ea1.assembly.stream.el9
openshift-ansible (Red Hat package) - update to 4.15.0-202402162207.p0.g1c9b99e.assembly.stream.el9
microshift (Red Hat package) - update to 4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
rust-afterburn (Red Hat package) - update to 5.4.3-2.rhaos4.15.el9
kernel (Red Hat package) - update to 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.54.1.rt14.339.el9_2
Red Hat Migration Toolkit for Applications - update to 7.0.3
Storage Protect Server - update to 8.1.23
IBM Security Verify Access - update to 10.0.9
Storage Protect Plus Server - update to 10.1.16.2
Red Hat OpenStack - update to 17.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
cockpit-podman - addressed in versions 46-1, 84.1-1
ostree (Red Hat package) - update to 2023.8-3.el9
rpm-ostree (Red Hat package) - update to 2024.2-1.el9
External References
Related Security Bulletins
- Marvin attack in Go programming language
- Red Hat Enterprise Linux 8 update for the container-tools:4.0 module
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat build of MicroShift
- Observable discrepancy in IBM Cloud Pak System
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Service Interconnect 1.5
- Red Hat Enterprise Linux 9 update for runc
- Red Hat Enterprise Linux 9 update for skopeo
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 9 update for containernetworking-plugins
- Multiple vulnerabilities in IBM Watson Discovery
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenStack 17 packages
- Multiple vulnerabilities in Red Hat OpenStack 17 packages
- Observable discrepancy in IBM Storage Protect Server
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Operations Dashboard
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Storage Protect Plus Server
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Anolis OS update for container-tools:4.0 module
- Anolis OS update for container-tools:an8 module
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0