RHSA-2024:4455MediumCVSS 6.5

Red Hat Security Advisory: OpenShift Virtualization 4.16.0 Images security update

Published
July 10, 2024
Last Modified
August 25, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2023-45857 — axios: exposure of confidential data stored in cookies CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28180 — jose-go: improper handling of highly compressed data

🎯 Affected products109

  • CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-controller-rhel9@sha256:071548d4f3f40fabe5640a034614ba851dfc7dd44d34e254ff6f14316bca5493_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-controller-rhel9@sha256:512f4e4ff422126f80d320046a5e382af23ae907ce1dfde89d839509c3bb74b9_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-operator-rhel9@sha256:a3503890693f678cfe2aa10a1654f457acc09256b526c1cdbbe16e3dcad25e36_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-operator-rhel9@sha256:e0ea05fcbeb5410202db5324df4a4e226f987c50384f0642e8fcba1756ea6216_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-server-rhel9@sha256:6652bcac93c626c7eb8a1e3cd02cb481d28cf798a868c8a6279ad0abcd44e718_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/aaq-server-rhel9@sha256:9f6ddda7f53a7fcb5d49ae2198296127e2f64d4de35a7ba94d939c89274f5f65_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:23efd84e61f779cec3178fc29e43395b195444b75267663f5da1c948c9c8fdb0_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/bridge-marker-rhel9@sha256:f3b2fffe4c033578e7553978b2543ef6d18e310485f0a8e8c6bc7d9e590256b9_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:41db645b78dab1cc23ae735705fb80f4583c553113862d4a6abf59a01d5d505f_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cluster-network-addons-operator-rhel9@sha256:9102ce4d7ad07be7d47999b1d15f356dedf90dacb0ce249fd5f5d9b7271fab1b_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:bef63bf31e1637cd7245c2da670bb89fbea1bbf0c2ba374eb5c4877dfc50c8ff_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-containernetworking-plugins-rhel9@sha256:ffba4dedfaef9af4079ee0dac56790f712d32690d7f65b7f880227a0d7c0e51a_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:0931d6c620f004ffc3508a5aad311ddc793290e03229047410d59adcfc5f92d6_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/cnv-must-gather-rhel9@sha256:8d4ebbaea042a3b03057a889acdee001c5d440e54596dbe5c79d0a42b8585de7_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:38b884ec0ff34001faba8ff794de6f24d78854a5d02220e7e698ceeaf6fd0c27_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hco-bundle-registry-rhel9@sha256:d77c2d87fd8662ee468b4201e102fef2a63fa632aca041831a86d517d414bc72_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:bfd35d9a41ec1299a2fb731c7bc59fa3e29f99a2adb5f35b6c0b1de3dc6d4e81_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-csi-driver-rhel9@sha256:f5480efb2f5da13c597cdb980ecac06a823091f8ef71a953fdad2c65dd881587_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:133a406e2ecd66493f60c017202ed5d8590746438c6ad6e1ec08a7ea820b6b61_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-operator-rhel9@sha256:6a567b98782553844c593b451575a8b3efca7510981b42ec612ed9c043e06c72_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:6bfe59a664845cd5c276fe1149a62b914833196c8ad2c8513b6004b60ad5a9a8_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hostpath-provisioner-rhel9@sha256:82eae4ac0150477978a037da657c2d92e4a5c3acd7c52216d90a2ae76df4f4cf_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:b4df0c8581b2c71a23a35f7f171c20408b8578b23d56607dd79ab15f4df9b74b_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-operator-rhel9@sha256:ec7b547ebe92be21ef909724e71d69e0c37abd56cd4d8094c463fdc39c56f6f1_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:27d74031de11e457425dcb856c5fb3178237b12807d49ecbaf7051cc2a48211e_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/hyperconverged-cluster-webhook-rhel9@sha256:5586d9c22a9c3bf2f5a2556f2dfc7f7c4e2fbbd0f0a44f1962164a6c46b0dcce_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:30a77dd0b6b663d13cf8b65c6da98bb3347619e8536c32914d5ef78ab9b5fbac_arm64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/kubemacpool-rhel9@sha256:cb591b994af004ff0c4f67b201fd8a7baf89117a25010e23deb6d4a9b0571675_amd64 as a component of CNV 4.16 for RHEL 9
  • container-native-virtualization/kubesecondarydns-rhel9@sha256:3fb0b2fed6443fa7e795676a13a6f3c3fa19629e55c3baee26c8f7435ff3ed9d_amd64 as a component of CNV 4.16 for RHEL 9
  • +79 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (179)