RHEA-2024:4022HighCVSS 7.5
Red Hat Enhancement Advisory: Red Hat OpenShift Pipelines Client tkn for 1.15.0 release
🔗 CVE IDs covered (5)
📋 Description
CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-28110 — cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-29902 — cosign: Malicious attachments can cause system-wide denial of service CVE-2024-29903 — cosign: Malicious artifects can cause machine-wide denial of service