RHSA-2025:19306HighCVSS 8.2
Red Hat Security Advisory: OpenShift Container Platform 4.15.59 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-45337 — golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto CVE-2024-48910 — dompurify: DOMPurify vulnerable to tampering by prototype pollution CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:19306
- externalhttps://access.redhat.com/security/cve/CVE-2024-45337
- externalhttps://access.redhat.com/security/cve/CVE-2024-48910
- externalhttps://access.redhat.com/security/cve/CVE-2025-22871
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_19306.json