RHSA-2024:10895MediumCVSS 5.9
Red Hat Security Advisory: Cost Management Metrics Operator Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-34155 — go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion
🎯 Affected products6
- Cost Management Metrics Operator 3.3.2
- registry.redhat.io/costmanagement/costmanagement-metrics-operator-bundle@sha256:448e65667b5c167699778b0056a18b31dc7ed95022c803217a2786d27d21e945_amd64 as a component of Cost Management Metrics Operator 3.3.2
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:1598a43c0733ca86a857124fd30c104180db6086419a903daac0711559948cd3_ppc64le as a component of Cost Management Metrics Operator 3.3.2
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:6a21d8db8b1b4d1cbb3ab9ab8186d8af36e883bdd9b8da27b91907d623f57a40_arm64 as a component of Cost Management Metrics Operator 3.3.2
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:85edd059d6196a5b0602f1c1b733d502fe44858ccb35f4cfd8bdf02b66a6ed3c_amd64 as a component of Cost Management Metrics Operator 3.3.2
- registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:f02cd3562cf7ea8011a6d40ec8563f34f2ec05c66574edff2fdc876919898ad4_s390x as a component of Cost Management Metrics Operator 3.3.2
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.openshift.com/container-platform/latest/operators/admin/olm- upgrading-operators.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:10895
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/cve/CVE-2024-34155
- externalhttps://docs.redhat.com/en/documentation/cost_management_service/1-latest/html/getting_started_with_cost_management/steps-to-cost-management
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10895.json