RHSA-2024:6235MediumCVSS 5.3

Red Hat Security Advisory: Red Hat Trusted Profile Analyzer 1.1.2

Published
September 3, 2024
Last Modified
August 1, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject

🎯 Affected products2

  • Red Hat Trusted Profile Analyzer Operator 1.1
  • registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:9142fe58fad28a8b469b17bdd84fe6bbcb6830811a3b31c671142ce109739455_amd64 as a component of Red Hat Trusted Profile Analyzer Operator 1.1

✅ Remediation

It is recommended that existing users of RHTPA 1.1.1 upgrade to 1.1.2. There are no changes to any data structures or API’s included within this release.

🔗 References (7)