RHSA-2024:5054HighCVSS 7.5
Red Hat Security Advisory: OpenShift Virtualization 4.16.1 Images security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-41818 — fast-xml-parser: ReDOS at currency parsing in currency.js
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2024:5054
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300499
- externalhttps://issues.redhat.com/browse/CNV-23540
- externalhttps://issues.redhat.com/browse/CNV-36845
- externalhttps://issues.redhat.com/browse/CNV-39739
- externalhttps://issues.redhat.com/browse/CNV-41081
- externalhttps://issues.redhat.com/browse/CNV-41538
- externalhttps://issues.redhat.com/browse/CNV-41948
- externalhttps://issues.redhat.com/browse/CNV-41962
- externalhttps://issues.redhat.com/browse/CNV-42128
- externalhttps://issues.redhat.com/browse/CNV-42157
- externalhttps://issues.redhat.com/browse/CNV-42223
- externalhttps://issues.redhat.com/browse/CNV-42365
- externalhttps://issues.redhat.com/browse/CNV-42482
- externalhttps://issues.redhat.com/browse/CNV-42508
- externalhttps://issues.redhat.com/browse/CNV-42700
- externalhttps://issues.redhat.com/browse/CNV-43206
- externalhttps://issues.redhat.com/browse/CNV-43209
- externalhttps://issues.redhat.com/browse/CNV-44478
- externalhttps://issues.redhat.com/browse/CNV-44506
- externalhttps://issues.redhat.com/browse/CNV-44592
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5054.json