RHSA-2024:3718MediumCVSS 9.9

Red Hat Security Advisory: OpenShift Container Platform 4.17.0 bug fix and security update

Published
October 1, 2024
Last Modified
May 26, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2023-3775 — hashicorp/vault: vault enterprise’s sentinel RGP policies allowed for cross-namespace denial of service CVE-2023-5077 — hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets CVE-2023-5954 — vault: inbound client requests can trigger a denial of service CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-7387 — openshift/builder: Path traversal allows command injection in privileged BuildContainer using docker build strategy CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-24789 — golang: archive/zip: Incorrect handling of certain ZIP files CVE-2024-25620 — helm: Dependency management path traversal CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-45496 — openshift-controller-manager: Elevated Build Pods Can Lead to Node Compromise in OpenShift

🔗 References (846)