RHSA-2024:4479HighCVSS 8.1
Red Hat Security Advisory: OpenShift Container Platform 4.14.33 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-6387 — openssh: regreSSHion - race condition in SSH allows RCE/DoS
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2024:4479
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294604
- externalhttps://issues.redhat.com/browse/OCPBUGS-31354
- externalhttps://issues.redhat.com/browse/OCPBUGS-32499
- externalhttps://issues.redhat.com/browse/OCPBUGS-36437
- externalhttps://issues.redhat.com/browse/OCPBUGS-36461
- externalhttps://issues.redhat.com/browse/OCPBUGS-36475
- externalhttps://issues.redhat.com/browse/OCPBUGS-36518
- externalhttps://issues.redhat.com/browse/OCPBUGS-36593
- externalhttps://issues.redhat.com/browse/OCPBUGS-36776
- externalhttps://issues.redhat.com/browse/OCPBUGS-5943
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4479.json