RHSA-2024:9885HighCVSS 7.5
Red Hat Security Advisory: Red Hat Trusted Profile Analyzer 1.2.0
🔗 CVE IDs covered (2)
📋 Description
CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2024:9885
- externalhttps://issues.redhat.com/browse/TC-1713
- externalhttps://issues.redhat.com/browse/TC-1721
- externalhttps://issues.redhat.com/browse/TC-1757
- externalhttps://issues.redhat.com/browse/TC-1769
- externalhttps://issues.redhat.com/browse/TC-1770
- externalhttps://issues.redhat.com/browse/TC-1799
- externalhttps://issues.redhat.com/browse/TC-1800
- externalhttps://issues.redhat.com/browse/TC-1801
- externalhttps://issues.redhat.com/browse/TC-1810
- externalhttps://issues.redhat.com/browse/TC-1815
- externalhttps://issues.redhat.com/browse/TC-1817
- externalhttps://issues.redhat.com/browse/TC-1818
- externalhttps://issues.redhat.com/browse/TC-1841
- externalhttps://issues.redhat.com/browse/TC-1842
- externalhttps://issues.redhat.com/browse/TC-1846
- externalhttps://issues.redhat.com/browse/TC-1847
- externalhttps://issues.redhat.com/browse/TC-1855
- externalhttps://issues.redhat.com/browse/TC-1857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311171
- externalhttps://docs.redhat.com/en/documentation/red_hat_trusted_profile_analyzer/1.2/html/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2024-45296
- externalhttps://access.redhat.com/security/cve/CVE-2024-45590
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9885.json