RHSA-2024:10917HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Jaeger) 3.4 release
🔗 CVE IDs covered (9)
📋 Description
CVE-2024-21536 — http-proxy-middleware: Denial of Service
CVE-2024-43796 — express: Improper Input Handling in Express Redirects
CVE-2024-43799 — send: Code Execution Vulnerability in Send Library
CVE-2024-43800 — serve-static: Improper Sanitization in serve-static
CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS
CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser
CVE-2024-45811 — vite: server.fs.deny is bypassed when using ?import&raw
CVE-2024-45812 — vite: XSS via DOM Clobbering gadget found in vite bundled scripts
CVE-2024-47068 — rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:10917
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/distributed_tracing/distributed-tracing-platform-jaeger
- externalhttps://access.redhat.com/security/cve/CVE-2024-21536
- externalhttps://access.redhat.com/security/cve/CVE-2024-43796
- externalhttps://access.redhat.com/security/cve/CVE-2024-43799
- externalhttps://access.redhat.com/security/cve/CVE-2024-43800
- externalhttps://access.redhat.com/security/cve/CVE-2024-45296
- externalhttps://access.redhat.com/security/cve/CVE-2024-45590
- externalhttps://access.redhat.com/security/cve/CVE-2024-45811
- externalhttps://access.redhat.com/security/cve/CVE-2024-45812
- externalhttps://access.redhat.com/security/cve/CVE-2024-47068
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10917.json