RHSA-2024:11256HighCVSS 7.5

Red Hat Security Advisory: Red Hat Trusted Profile Analyzer 1.2.1

Published
December 17, 2024
Last Modified
September 6, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-21538 — cross-spawn: regular expression denial of service

🎯 Affected products2

  • Red Hat Trusted Profile Analyzer 1.2
  • registry.redhat.io/rhtpa/rhtpa-guac-rhel9@sha256:9cc0e1374aa5e6ff8caf86d9bbd6f9c2dfa14d812ad99ae653a2fbb8ec124f30_amd64 as a component of Red Hat Trusted Profile Analyzer 1.2

✅ Remediation

It is recommended that existing users of RHTPA 1.2.0 upgrade to 1.2.1. For more information please refer to the Release Notes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time.

🔗 References (19)