RHSA-2024:11255HighCVSS 7.5

Red Hat Security Advisory: Red Hat Trusted Profile Analyzer 1.2.1

Published
December 17, 2024
Last Modified
September 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-21538 — cross-spawn: regular expression denial of service

🎯 Affected products2

  • Red Hat Trusted Profile Analyzer 1.2
  • registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:8c6e51e26ca9a1d4d4fc9e90650103e60360cf0571533c56fbd08dac3007efbe_amd64 as a component of Red Hat Trusted Profile Analyzer 1.2

✅ Remediation

It is recommended that existing users of RHTPA 1.2.0 upgrade to 1.2.1. For more information please refer to the Release Notes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time.

🔗 References (19)