RHSA-2024:1891HighCVSS 8.1
Red Hat Security Advisory: OpenShift Container Platform 4.14.22 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-1139 — cluster-monitoring-operator: credentials leak CVE-2024-1725 — kubevirt-csi: PersistentVolume allows access to HCP's root node
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2024:1891
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265398
- externalhttps://issues.redhat.com/browse/OCPBUGS-25145
- externalhttps://issues.redhat.com/browse/OCPBUGS-27108
- externalhttps://issues.redhat.com/browse/OCPBUGS-30898
- externalhttps://issues.redhat.com/browse/OCPBUGS-31487
- externalhttps://issues.redhat.com/browse/OCPBUGS-31504
- externalhttps://issues.redhat.com/browse/OCPBUGS-31648
- externalhttps://issues.redhat.com/browse/OCPBUGS-31669
- externalhttps://issues.redhat.com/browse/OCPBUGS-31677
- externalhttps://issues.redhat.com/browse/OCPBUGS-31731
- externalhttps://issues.redhat.com/browse/OCPBUGS-31844
- externalhttps://issues.redhat.com/browse/OCPBUGS-31862
- externalhttps://issues.redhat.com/browse/OCPBUGS-31885
- externalhttps://issues.redhat.com/browse/OCPBUGS-31886
- externalhttps://issues.redhat.com/browse/OCPBUGS-32112
- externalhttps://issues.redhat.com/browse/OCPBUGS-32137
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1891.json