RHSA-2024:2625: Important: rhc-worker-script security and enhancement update
Important: rhc-worker-script security and enhancement update
Other sources
The rhc-worker-script packages provide Remote Host Configuration (rhc) worker for executing an interpreted programming language script on hosts managed by Red Hat Insights.<br>Security Fix(es):<br><li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Enhancement(s):<br><li> Include deps information in rhc-worker-script binary (JIRA:HMS-3983)</li> <li> Set more granular log level for the scripts (JIRA:HMS-3837)</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2625?
The severity of RHSA-2024:2625 is classified as Important.
What is the main purpose of the rhc-worker-script package affected by RHSA-2024:2625?
The rhc-worker-script package is used for executing interpreted programming language scripts on hosts managed by Red Hat Insights.
How do I fix the vulnerability identified in RHSA-2024:2625?
To fix the vulnerability in RHSA-2024:2625, you should update the rhc-worker-script package to version 0.8-1.el7_9.
Which systems are affected by RHSA-2024:2625?
The systems affected by RHSA-2024:2625 include multiple versions of Red Hat Enterprise Linux, such as Server, Workstation, Desktop, and Scientific Computing.
Is there a specific package version recommended for RHSA-2024:2625?
Yes, the recommended package version to resolve RHSA-2024:2625 is rhc-worker-script version 0.8-1.el7_9.