RHSA-2024:1557: Critical: Errata Advisory for Red Hat OpenShift Builds 1.0.1
Critical: Errata Advisory for Red Hat OpenShift Builds 1.0.1
Other sources
Red Hat OpenShift Builds 1.0.Security Fix(es): CVE-2023-48795 ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2023-49569 go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2023-49568 go-git: Maliciously crafted Git server replies can cause DoS on go-git clients For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1557?
The severity of RHSA-2024:1557 is classified as critical.
What vulnerabilities are addressed in RHSA-2024:1557?
RHSA-2024:1557 addresses CVE-2023-48795 and CVE-2023-49569, related to security issues in ssh and go-git.
How do I fix RHSA-2024:1557?
To fix RHSA-2024:1557, it is recommended to apply the latest security updates for Red Hat OpenShift Builds.
Which products are affected by RHSA-2024:1557?
RHSA-2024:1557 affects various versions of Red Hat OpenShift Builds, including those for IBM Power, IBM Z and LinuxONE, and ARM.
What is the impact of CVE-2023-48795 in RHSA-2024:1557?
CVE-2023-48795 presents a prefix truncation attack on the Binary Packet Protocol, which can compromise ssh security.