RHEA-2024:4022HighCVSS 7.5

Red Hat Enhancement Advisory: Red Hat OpenShift Pipelines Client tkn for 1.15.0 release

Published
June 20, 2024
Last Modified
June 2, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-28110 — cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-29902 — cosign: Malicious attachments can cause system-wide denial of service CVE-2024-29903 — cosign: Malicious artifects can cause machine-wide denial of service

🔗 References (4)