RHSA-2024:11256HighCVSS 7.5
Red Hat Security Advisory: Red Hat Trusted Profile Analyzer 1.2.1
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-7254 — protobuf: StackOverflow vulnerability in Protocol Buffers CVE-2024-21536 — http-proxy-middleware: Denial of Service CVE-2024-21538 — cross-spawn: regular expression denial of service
🎯 Affected products2
- Red Hat Trusted Profile Analyzer 1.2
- registry.redhat.io/rhtpa/rhtpa-guac-rhel9@sha256:9cc0e1374aa5e6ff8caf86d9bbd6f9c2dfa14d812ad99ae653a2fbb8ec124f30_amd64 as a component of Red Hat Trusted Profile Analyzer 1.2
✅ Remediation
It is recommended that existing users of RHTPA 1.2.0 upgrade to 1.2.1. For more information please refer to the Release Notes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat Product Security does not have any mitigation recommendations at this time.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2024:11256
- externalhttps://issues.redhat.com/browse/TC-1865
- externalhttps://issues.redhat.com/browse/TC-1873
- externalhttps://issues.redhat.com/browse/TC-1880
- externalhttps://issues.redhat.com/browse/TC-1892
- externalhttps://issues.redhat.com/browse/TC-1928
- externalhttps://issues.redhat.com/browse/TC-1947
- externalhttps://issues.redhat.com/browse/TC-1970
- externalhttps://issues.redhat.com/browse/TC-1868
- externalhttps://issues.redhat.com/browse/TC-1937
- externalhttps://issues.redhat.com/browse/TC-1795
- externalhttps://issues.redhat.com/browse/TC-1824
- externalhttps://issues.redhat.com/browse/TC-1870
- externalhttps://docs.redhat.com/en/documentation/red_hat_trusted_profile_analyzer/1.2.1/html/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2024-21536
- externalhttps://access.redhat.com/security/cve/CVE-2024-21538
- externalhttps://access.redhat.com/security/cve/CVE-2024-7254
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_11256.json