RHSA-2024:2730: Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update
Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update
Other sources
This project aims to provide the possibility to switch from Sensu-based<br>availability monitoring solution to a monitoring solution based on collectd<br>with AMQP-1.0 messaging bus.<br>Security Fix(es):<br><li> golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)</li> <li> net/http/internal: Denial of Service (DoS) via Resource Consumption via</li> HTTP requests (CVE-2023-39326)<br><li> crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.</li> (CVE-2023-45287)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2730?
RHSA-2024:2730 is classified as an important security update for Red Hat OpenStack Platform 17.1.
How do I fix RHSA-2024:2730?
To fix RHSA-2024:2730, update the collectd-sensubility package to version 0.2.1-3.el9.
What software is affected by RHSA-2024:2730?
RHSA-2024:2730 affects the Red Hat OpenStack Platform 17.1 and the collectd-sensubility package.
What are the changes included in RHSA-2024:2730?
RHSA-2024:2730 includes security fixes related to the monitoring solution in Red Hat OpenStack.
Do I need to restart my system after applying RHSA-2024:2730?
It is recommended to restart your system after applying RHSA-2024:2730 to ensure all updates take effect.