RHSA-2024:4150MediumCVSS 5.9
Red Hat Security Advisory: OpenShift Container Platform 4.15.20 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🎯 Affected products156
- Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:440045ba65f418348618fbf0e1838dca297043353d80b167fa735e1864cc991d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:54154d58ffeccdbcb0fe53cc0bba568d44faffc264797800be0241e9ec413e19_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:72be9aebf64a5a6a2fcb8021408f7a81a215cd587c51e1187c8a5dba76017bc1_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/frr-rhel9@sha256:b1ff24fa97db72dba87b6bd8fd61425941ec955671dfa990a8ea5d4b499ada1f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:50fc191770a322262195ecef4a6c073b7b15b1709501cfebf99cab7f6751506f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:5857925ad3264c1f39a0acce9a59659498b3b691835605c5622a8d7e0b95830e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:800e621d2c5f2a8e311534126fea784b51331a76a1d0c20f4093e48cfb46283c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9-operator@sha256:e802067595bc44e4c97047d3925a2dbbc8934c2bc27d2cfffb37b3a8856516b9_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:3058fa0ee8fa529713785407e59b290cf130dc1ac8fc1762130247e991b9af2f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:5b54019d4731f08f9a2b5fb4d3f65c425359a9a1f8c18058c56839ae314cd918_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:cbd34951e9b8e617fdb37a13e26de67f21581091039c0bb331d5350a0d500db4_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ingress-node-firewall-rhel9@sha256:d64cbfc7d0e3df3a533fe0d2e51de4c0807f6e499d7a8c32daaffb0a6ff09dc4_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:0fefed700fb83bb4e943bf7f33b96d5a359aadd491762a0f727b2a70c34cdcc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:189d22b5d40d1f690844b3a30fc6f787153ce0b946e6bf7ae1bb3a649e052fc5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:6881a0a47462901ba19bd218c9f04176f4aa81d22650581931165b80b5045271_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/kubernetes-nmstate-rhel9-operator@sha256:eae1242aa6cc49773525aaaace2f61aa10638dacf3fe086986e150e3a1507468_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:0ad7c982893b642dac083796cbc13de07832697b8fb0e4164c2c82732ed6b11b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:3335a30e0fde8632205b463291c632e76913301dc12504c8b93ccb9d893e09c3_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:4806dcf876c3133d219df44dbb14dd4db708ac1143bb5ccd98bd848b378b8794_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9-operator@sha256:b59c314aa5c5d99605f525294d4be96b4c1cf96adbea123a0330ae336e0f7593_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:6abc0f1041a2dfaa99d239f8f97c4001dcafaca18ab65d9d39417dc799cac996_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:7aefba1e6bcec7fa44e39be1bcc871d7df22e287a09db7527249bc9bda7c0828_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:e2d7448039b36cc28543e0b4b46bc0268e8b6578cce4ec9ab82a3e6562f6c838_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/metallb-rhel9@sha256:f6e141109e97ec90e86c27d25b7b8a181aab33c6da07eaa839ce3ff3455224e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:411cd46fd20496736eb3bc0d4c680df0a7133a39ec096e66d7c5d47c493c7cc9_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:4a757acd66dbbaaf89c7ad0822acee9f778f05c103ff3b9c249459861755bc2c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:5cd875ff18b482d0affe132cda5f8adcd80b94b7c36b4e543ecb49a96da641d2_s390x as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/nmstate-console-plugin-rhel8@sha256:f736c9b5bf565dcc73427335695ecaf5605d521cd765c0432b5bc5f76f07baba_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- openshift4/ose-ansible-operator@sha256:01261218546bd973942e998d5353ee0598653bd37c717af59d7c3c6aa48bc372_s390x as a component of Red Hat OpenShift Container Platform 4.15
- +126 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.15/release_notes/ocp-4-15-release-notes.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.