RHSA-2024:4173MediumCVSS 5.9
Red Hat Security Advisory: Red Hat build of Cryostat 3.0.0: new RHEL 8 container image security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-30171 — bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)
🎯 Affected products19
- Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-db-rhel8@sha256:e3bdab63bdfa8f8bd586e35c3a3c8fe5dc6bbcb1a4a58286b61239f3b71c9da7_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-db-rhel8@sha256:f46e8d58e38cc7a89f30ad7d0cb9c216f107628c2913ccec2361c91f8f6a7f7f_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-grafana-dashboard-rhel8@sha256:31237230e7d52fd09434efff343043d8c1588eff15b5d99bcdf938a1b739613d_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-grafana-dashboard-rhel8@sha256:3679ad644998b29fe5f356b0dd7494ff3356a09ba8101fa41cfdf54ac0e7461d_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-operator-bundle@sha256:1787c8b5cff79d2fdd6f38bd4dfd4e7a7d3485dbb3493e134e9f344ab6b1354b_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-operator-bundle@sha256:ca41b2d1ce8de6065d452d11e81b648c7c52a5ebb99921f20a72218373c57206_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8@sha256:4959f510d66b7960eb04125d4efb5aa179212049ef0778ebd10fbd5d11ce2786_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8@sha256:52620ece35d7c05f9aa5ed9f97f76d2cad0a6eb6ffa61e26608919e24fcf8bb0_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-reports-rhel8@sha256:2d7c8bd9040222ce5a13403db92f8b323e268465ff17e5347c8f15ef976b356a_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-reports-rhel8@sha256:7803f76d816122212fb2e0f20d9ecbab29e4c287ffba7be3464b37ec06d51219_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-rhel8-operator@sha256:18b1cccd75118ad3e84467f048018353ad33437497b88a8d56154fdf0b010092_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-rhel8-operator@sha256:9a09c2579d683325936a3ee69129c156b09f2e7c05d0ed40ab01a30b365a2d18_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-rhel8@sha256:14b8f92b9e754d0dc6e107d88b52fddb5d5ca11d26e7d41178c9316c45ab29d9_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-rhel8@sha256:9593de391de6fbef67c3410e6b39066306b8047fb140079617ca3522a782ebb3_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-storage-rhel8@sha256:a63472e6434616e815f1cbd776c0bf5ee5a112d82312a61885cc4018a5695f81_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/cryostat-storage-rhel8@sha256:e38803c79654de50129cca99c94ab373c4b3f028601bf690deb8b96b3b32f7bb_arm64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/jfr-datasource-rhel8@sha256:41abaab9901edeab4b43ee8dc472fc58d67cf7a28dc61eaeee1192095fbee277_amd64 as a component of Cryostat 3 on RHEL 8
- cryostat-tech-preview/jfr-datasource-rhel8@sha256:b50ae0b0cb72db2bc9e24bec3f19933a3c8e8fb9148bc78b5b60e9f6cf37f13f_arm64 as a component of Cryostat 3 on RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.