RHSA-2024:1874: Moderate: rhc-worker-script security and enhancement update
Moderate: rhc-worker-script security and enhancement update
Other sources
The rhc-worker-script packages provide Remote Host Configuration (rhc) worker for executing an interpreted programming language script on hosts managed by Red Hat Insights.Security Fix(es): golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [rhc-worker-script] (CVE-2024-24786) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Enhancement(s): Allow users to specify environment variables through the rhc-worker-script configuration file to be passed down to the scripts being executed (HMS-3843)
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1874?
The severity of RHSA-2024:1874 is classified as moderate.
What does the RHSA-2024:1874 update address?
RHSA-2024:1874 addresses security and enhancement updates for the rhc-worker-script packages.
How do I fix RHSA-2024:1874?
To fix RHSA-2024:1874, update rhc-worker-script to version 0.7-1.el7_9.
What systems are affected by RHSA-2024:1874?
RHSA-2024:1874 affects systems running Red Hat Enterprise Linux and its derivatives.
Is RHSA-2024:1874 applicable to both x86_64 and other architectures?
Yes, RHSA-2024:1874 includes updates for the x86_64 architecture as well as other supported architectures.