RHSA-2024:0845: Critical: OpenShift Container Platform 4.13.34 security update
Critical: OpenShift Container Platform 4.13.34 security update
Other sources
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> go-git: Maliciously crafted Git server replies can lead to path traversal</li> and RCE on go-git clients (CVE-2023-49569)<br><li> go-git: Maliciously crafted Git server replies can cause DoS on go-git</li> clients (CVE-2023-49568)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s)<br>listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0845?
RHSA-2024:0845 is classified as critical due to the potential for exploitation of the vulnerability.
How do I fix RHSA-2024:0845?
To fix RHSA-2024:0845, apply the latest security updates for your version of OpenShift Container Platform as recommended by Red Hat.
Which versions of OpenShift Container Platform are affected by RHSA-2024:0845?
RHSA-2024:0845 affects various versions including Red Hat OpenShift Container Platform for ARM 64, Power, and IBM Z and LinuxONE.
What types of vulnerabilities are addressed in RHSA-2024:0845?
RHSA-2024:0845 addresses vulnerabilities related to the go-git component that could be exploited by attackers.
Is there a workaround for RHSA-2024:0845 until I can apply the fix?
There may not be a specific workaround for RHSA-2024:0845; it is advised to apply patches as soon as possible to mitigate risks.