Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.0 security, enhancement, & bug fix update
🔗 CVE IDs covered (31)
📋 Description
CVE-2021-35937 — rpm: TOCTOU race in checks for unsafe symlinks CVE-2021-35938 — rpm: races with chown/chmod/capabilities calls during installation CVE-2021-35939 — rpm: checks for unsafe symlinks are not performed for intermediary directories CVE-2023-3462 — Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration CVE-2023-5363 — openssl: Incorrect cipher key and IV length processing CVE-2023-5954 — vault: inbound client requests can trigger a denial of service CVE-2023-5981 — gnutls: timing side-channel in the RSA-PSK authentication CVE-2023-7104 — sqlite: heap-buffer-overflow at sessionfuzz CVE-2023-24532 — golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results CVE-2023-26159 — follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() CVE-2023-27043 — python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple CVE-2023-28486 — sudo: Sudo does not escape control characters in log messages CVE-2023-28487 — sudo: Sudo does not escape control characters in sudoreplay output CVE-2023-29406 — golang: net/http: insufficient sanitization of Host header CVE-2023-29409 — golang: crypto/tls: slow verification of certificate chains containing large RSA keys CVE-2023-39318 — golang: html/template: improper handling of HTML-like comments within script contexts CVE-2023-39319 — golang: html/template: improper handling of special tags within script contexts CVE-2023-39321 — golang: crypto/tls: panic when processing post-handshake message on QUIC connections CVE-2023-39322 — golang: crypto/tls: lack of a limit on buffered post-handshake CVE-2023-39615 — libxml2: crafted xml can cause global buffer overflow CVE-2023-42282 — nodejs-ip: arbitrary code execution via the isPublic() function CVE-2023-42465 — sudo: Targeted Corruption of Register and Stack Variables CVE-2023-43646 — get-func-name: ReDoS in chai module CVE-2023-43804 — python-urllib3: Cookie request header isn't stripped during cross-origin redirects CVE-2023-45803 — urllib3: Request body not stripped after redirect from 303 status changes request method to GET CVE-2023-46218 — curl: information disclosure by exploiting a mixed case flaw CVE-2023-48631 — css-tools: regular expression denial of service (ReDoS) when parsing CSS CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-51385 — openssh: potential command injection via shell metacharacters CVE-2024-0553 — gnutls: incomplete fix for CVE-2023-5981 CVE-2024-0567 — gnutls: rejects certificate chain with distributed trust
🔗 References (160)
- selfhttps://access.redhat.com/errata/RHSA-2024:1383
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_data_foundation/4.15/html/4.15_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2022467
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2130266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165128
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165907
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196858
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2207925
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208302
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209616
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2210970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213885
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228785
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2229670
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231076
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2231860
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2233010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234479
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236384
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237427
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237895
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2237920
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239208
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239590
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2239608
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2240756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2240908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241268
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2242309
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244569
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2244570
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246084
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2246993
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247094
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247313
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247714
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247731
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2247748
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248117
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248666
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2248832
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2249678
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2249844
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250092
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250636
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2250995
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2252035
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2252756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253257
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254159
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254216
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254333
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255036
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255194
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255320
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255328
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255333
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255411
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255491
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255501
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255508
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255586
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2255890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256161
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256580
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256597
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256633
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256637
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256725
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257222
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257427
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257634
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257674
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257694
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257711
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258357
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258560
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259187
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259476
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259852
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260050
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260131
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260279
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2260818
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2261936
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2263319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2263472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2263984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264002
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2264825
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265124
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265514
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266583
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267209
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267712
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2267885
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268407
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268959
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1383.json