RHSA-2023:6832HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.14.0 security, enhancement & bug fix update

Published
November 8, 2023
Last Modified
May 23, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2021-4048 — lapack: Out-of-bounds read in *larrv CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2023-2121 — hashicorp: html injection into web ui CVE-2023-3462 — Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-5077 — hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2023-44487 — HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)

🔗 References (180)