RHSA-2024:6235MediumCVSS 5.3
Red Hat Security Advisory: Red Hat Trusted Profile Analyzer 1.1.2
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-39249 — nodejs-async: Regular expression denial of service while parsing function in autoinject
🎯 Affected products2
- Red Hat Trusted Profile Analyzer Operator 1.1
- registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:9142fe58fad28a8b469b17bdd84fe6bbcb6830811a3b31c671142ce109739455_amd64 as a component of Red Hat Trusted Profile Analyzer Operator 1.1
✅ Remediation
It is recommended that existing users of RHTPA 1.1.1 upgrade to 1.1.2. There are no changes to any data structures or API’s included within this release.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2024:6235
- externalhttps://access.redhat.com/security/cve/CVE-2024-39249
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://issues.redhat.com/browse/TC-1640
- externalhttps://issues.redhat.com/browse/TC-1730
- externalhttps://docs.redhat.com/en/documentation/red_hat_trusted_profile_analyzer/1.1/html/release_notes/index
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6235.json