RHSA-2024:1946MediumCVSS 6.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.5.1 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-26159 — follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-28849 — follow-redirects: Possible credential leak
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2024:1946
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://issues.redhat.com/browse/OSSM-5541
- externalhttps://issues.redhat.com/browse/OSSM-5902
- externalhttps://issues.redhat.com/browse/OSSM-5959
- externalhttps://issues.redhat.com/browse/OSSM-5960
- externalhttps://issues.redhat.com/browse/OSSM-5961
- externalhttps://issues.redhat.com/browse/OSSM-5997
- externalhttps://issues.redhat.com/browse/OSSM-6080
- externalhttps://issues.redhat.com/browse/OSSM-6099
- externalhttps://issues.redhat.com/browse/OSSM-6101
- externalhttps://issues.redhat.com/browse/OSSM-6148
- externalhttps://issues.redhat.com/browse/OSSM-6163
- externalhttps://issues.redhat.com/browse/OSSM-6177
- externalhttps://issues.redhat.com/browse/OSSM-6261
- externalhttps://issues.redhat.com/browse/OSSM-6264
- externalhttps://issues.redhat.com/browse/OSSM-6289
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1946.json