RHSA-2024:6755HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.16.2 security and bug fix update
🔗 CVE IDs covered (8)
📋 Description
CVE-2023-39325 — golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file CVE-2024-24789 — golang: archive/zip: Incorrect handling of certain ZIP files CVE-2024-28176 — jose: resource exhaustion CVE-2024-28863 — node-tar: denial of service while parsing a tar file due to lack of folders depth validation CVE-2024-29180 — webpack-dev-middleware: lack of URL validation may lead to file leak CVE-2024-37890 — nodejs-ws: denial of service when handling a request with many HTTP headers CVE-2024-41818 — fast-xml-parser: ReDOS at currency parsing in currency.js
🔗 References (29)
- selfhttps://access.redhat.com/errata/RHSA-2024:6755
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/cve/CVE-2024-6104
- externalhttps://access.redhat.com/security/cve/CVE-2024-8421
- externalhttps://access.redhat.com/security/cve/CVE-2024-24789
- externalhttps://access.redhat.com/security/cve/CVE-2024-28176
- externalhttps://access.redhat.com/security/cve/CVE-2024-28863
- externalhttps://access.redhat.com/security/cve/CVE-2024-29180
- externalhttps://access.redhat.com/security/cve/CVE-2024-37890
- externalhttps://access.redhat.com/security/cve/CVE-2024-41818
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290526
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2292777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2293200
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300022
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300289
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2303177
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2303414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2304074
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2309710
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310210
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6755.json