RHSA-2024:1859MediumCVSS 7.5
Red Hat Security Advisory: OpenShift API for Data Protection (OADP) 1.3.1 security and bug fix update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-45142 — opentelemetry: DoS vulnerability in otelhttp CVE-2023-45287 — golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28180 — jose-go: improper handling of highly compressed data
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHSA-2024:1859
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2245180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://issues.redhat.com/browse/OADP-1912
- externalhttps://issues.redhat.com/browse/OADP-2866
- externalhttps://issues.redhat.com/browse/OADP-3005
- externalhttps://issues.redhat.com/browse/OADP-3038
- externalhttps://issues.redhat.com/browse/OADP-3041
- externalhttps://issues.redhat.com/browse/OADP-3044
- externalhttps://issues.redhat.com/browse/OADP-3051
- externalhttps://issues.redhat.com/browse/OADP-3055
- externalhttps://issues.redhat.com/browse/OADP-3189
- externalhttps://issues.redhat.com/browse/OADP-3326
- externalhttps://issues.redhat.com/browse/OADP-3379
- externalhttps://issues.redhat.com/browse/OADP-3390
- externalhttps://issues.redhat.com/browse/OADP-3395
- externalhttps://issues.redhat.com/browse/OADP-3486
- externalhttps://issues.redhat.com/browse/OADP-3495
- externalhttps://issues.redhat.com/browse/OADP-3598
- externalhttps://issues.redhat.com/browse/OADP-3710
- externalhttps://issues.redhat.com/browse/OADP-3821
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1859.json