RHSA-2024:8235HighCVSS 8.8
Red Hat Security Advisory: OpenShift Container Platform 4.14.39 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-29401 — golang-github-gin-gonic-gin: Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-2961 — glibc: Out of bounds write in iconv may lead to remote code execution CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-44082 — openstack-ironic: Specially crafted image may allow authenticated users to gain access to potentially sensitive data
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2024:8235
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2216957
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2309331
- externalhttps://issues.redhat.com/browse/OCPBUGS-25727
- externalhttps://issues.redhat.com/browse/OCPBUGS-32266
- externalhttps://issues.redhat.com/browse/OCPBUGS-37353
- externalhttps://issues.redhat.com/browse/OCPBUGS-37552
- externalhttps://issues.redhat.com/browse/OCPBUGS-39019
- externalhttps://issues.redhat.com/browse/OCPBUGS-41246
- externalhttps://issues.redhat.com/browse/OCPBUGS-41836
- externalhttps://issues.redhat.com/browse/OCPBUGS-41918
- externalhttps://issues.redhat.com/browse/OCPBUGS-42517
- externalhttps://issues.redhat.com/browse/OCPBUGS-42518
- externalhttps://issues.redhat.com/browse/OCPBUGS-42533
- externalhttps://issues.redhat.com/browse/OCPBUGS-42567
- externalhttps://issues.redhat.com/browse/OCPBUGS-42603
- externalhttps://issues.redhat.com/browse/OCPBUGS-42757
- externalhttps://issues.redhat.com/browse/OCPBUGS-42828
- externalhttps://issues.redhat.com/browse/OCPBUGS-42986
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8235.json