RHSA-2024:8534MediumCVSS 7.5
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Release Update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-10033 — aap-gateway: XSS on aap-gateway CVE-2024-22189 — quic-go: memory exhaustion attack against QUIC's connection ID mechanism CVE-2024-41989 — python-django: Memory exhaustion in django.utils.numberformat.floatformat() CVE-2024-45230 — python-django: Potential denial-of-service vulnerability in django.utils.html.urlize()
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:8534
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302433
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2319162
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8534.json