RHSA-2024:7725HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.5.5
🔗 CVE IDs covered (9)
📋 Description
CVE-2024-23326 — envoy: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode
CVE-2024-30255 — envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood
CVE-2024-32475 — envoy: abnormal termination when using auto_sni with authority header longer than 255 characters
CVE-2024-32976 — envoy: Brotli decompressor infinite loop
CVE-2024-43788 — webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule
CVE-2024-43799 — send: Code Execution Vulnerability in Send Library
CVE-2024-43800 — serve-static: Improper Sanitization in serve-static
CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser
CVE-2024-45806 — envoy: Potential to manipulate x-envoy headers from external sources
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:7725
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259228
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272986
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2276149
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2283145
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313683
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7725.json