RHSA-2024:7922HighCVSS 8.8

Red Hat Security Advisory: OpenShift Container Platform 4.17.1 bug fix and security update

Published
October 16, 2024
Last Modified
May 26, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2023-3462 — Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-6345 — pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools CVE-2024-6508 — openshift-console: OAuth2 insufficient state parameter entropy CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-24791 — net/http: Denial of service due to improper 100-continue handling in net/http CVE-2024-27289 — pgx: SQL Injection via Line Comment Creation CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS

🔗 References (109)