First published: Mon Dec 16 2024(Updated: )
An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by authenticated sources.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OSE OLM CatalogD Container |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12698 has a critical severity rating due to its potential impact on authenticated streams.
To mitigate CVE-2024-12698, update your Red Hat ose-olm-catalogd-container to the latest patched version.
CVE-2024-12698 affects systems running the Red Hat OSE OLM CatalogD Container.
No, CVE-2024-12698 is an incomplete fix for previously identified vulnerabilities (CVE-2023-39325 and CVE-2023-44487).
Yes, CVE-2024-12698 can be exploited by attackers to access unauthenticated streams, posing a security risk.