RHSA-2024:5202MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.12.63 packages and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-37298 — gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:5202
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295010
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5202.json