RHSA-2024:1507: Moderate: logging for Red Hat OpenShift security update
Logging for Red Hat OpenShift is an opinionated collector and normalizer of application, infrastructure, and audit logs. It is intended to be used for forwarding logs to various supported systems.<br>Security Fix(es):<br><li> golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Moderate: logging for Red Hat OpenShift security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1507?
The severity of RHSA-2024:1507 is classified as important.
How do I fix RHSA-2024:1507?
To address RHSA-2024:1507, update the Logging Subsystem for Red Hat OpenShift to the latest version provided in the advisory.
What products are affected by RHSA-2024:1507?
RHSA-2024:1507 affects the Logging Subsystem for Red Hat OpenShift on various architectures including IBM Z, IBM Power, and ARM 64.
What are the security fixes included in RHSA-2024:1507?
RHSA-2024:1507 includes security fixes for vulnerabilities in golang-protobuf related to encoding and JSON handling.
Is there a recommended action for users of Red Hat OpenShift related to RHSA-2024:1507?
Users of Red Hat OpenShift are recommended to apply the updates outlined in RHSA-2024:1507 as soon as possible.