RHSA-2024:8974HighCVSS 8.2
Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.12.0 security and bug fixes
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-37788 — goproxy: Denial of service (DoS) via unspecified vectors. CVE-2024-1442 — grafana: Improper priviledge managent for users with data source permissions CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-48949 — elliptic: Missing Validation in Elliptic's EDDSA Signature Verification
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:8974
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://issues.redhat.com/browse/ACM-11757
- externalhttps://issues.redhat.com/browse/ACM-12215
- externalhttps://issues.redhat.com/browse/ACM-12372
- externalhttps://issues.redhat.com/browse/ACM-12738
- externalhttps://issues.redhat.com/browse/ACM-13066
- externalhttps://issues.redhat.com/browse/ACM-13149
- externalhttps://issues.redhat.com/browse/ACM-14172
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8974.json