Lucene search

K
redhatRedHatRHSA-2024:5547
HistoryAug 19, 2024 - 7:36 a.m.

(RHSA-2024:5547) Important: Red Hat OpenShift Data Foundation 4.16.1 bug fix and security update

2024-08-1907:36:00
access.redhat.com
1
red hat openshift
data foundation
bug fix
security update
scalable
persistent storage
multi-cloud
data management

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3-compatible API.

Security Fix(es):

  • golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788)
  • golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)
  • go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
  • nodejs-ws: denial of service when handling a request with many HTTP headers (CVE-2024-37890)

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High