RHSA-2024:6409MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.15.31 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2024:6409
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://issues.redhat.com/browse/OCPBUGS-31467
- externalhttps://issues.redhat.com/browse/OCPBUGS-33938
- externalhttps://issues.redhat.com/browse/OCPBUGS-34842
- externalhttps://issues.redhat.com/browse/OCPBUGS-37049
- externalhttps://issues.redhat.com/browse/OCPBUGS-37408
- externalhttps://issues.redhat.com/browse/OCPBUGS-38377
- externalhttps://issues.redhat.com/browse/OCPBUGS-38400
- externalhttps://issues.redhat.com/browse/OCPBUGS-38712
- externalhttps://issues.redhat.com/browse/OCPBUGS-38895
- externalhttps://issues.redhat.com/browse/OCPBUGS-38939
- externalhttps://issues.redhat.com/browse/OCPBUGS-38943
- externalhttps://issues.redhat.com/browse/OCPBUGS-39077
- externalhttps://issues.redhat.com/browse/OCPBUGS-39085
- externalhttps://issues.redhat.com/browse/OCPBUGS-39112
- externalhttps://issues.redhat.com/browse/OCPBUGS-39172
- externalhttps://issues.redhat.com/browse/OCPBUGS-39463
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6409.json