RHSA-2023:4986MediumCVSS 9.8
Red Hat Security Advisory: Red Hat OpenShift Distributed Tracing 2.9.0 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-24534 — golang: net/http, net/textproto: denial of service from excessive memory allocation CVE-2023-24536 — golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption CVE-2023-24537 — golang: go/parser: Infinite loop in parsing CVE-2023-24538 — golang: html/template: backticks not treated as string delimiters
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:4986
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184484
- externalhttps://issues.redhat.com/browse/TRACING-2968
- externalhttps://issues.redhat.com/browse/TRACING-3091
- externalhttps://issues.redhat.com/browse/TRACING-3142
- externalhttps://issues.redhat.com/browse/TRACING-3143
- externalhttps://issues.redhat.com/browse/TRACING-3147
- externalhttps://issues.redhat.com/browse/TRACING-3173
- externalhttps://issues.redhat.com/browse/TRACING-3204
- externalhttps://issues.redhat.com/browse/TRACING-3213
- externalhttps://issues.redhat.com/browse/TRACING-3243
- externalhttps://issues.redhat.com/browse/TRACING-3312
- externalhttps://issues.redhat.com/browse/TRACING-3322
- externalhttps://issues.redhat.com/browse/TRACING-3396
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4986.json