RHSA-2024:3868: Important: Network Observability 1.6.0 for OpenShift
Important: Network Observability 1.6.0 for OpenShift
Other sources
Network Observability 1.6.0<br>Security Fix(es):<br><li> CVE-2024-29180 webpack-dev-middleware: lack of URL validation may lead to file leak</li> <li> CVE-2024-24786 golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON</li> <li> CVE-2023-42282 nodejs-ip: arbitrary code execution via the isPublic() function</li> <li> CVE-2023-39326 golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests</li> <li> CVE-2024-28849 follow-redirects: Possible credential leak</li> <li> CVE-2024-24783 golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm</li> <li> CVE-2023-45289 golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect</li> <li> CVE-2023-45290 golang: net/<a href="http:" target="blank">http:</a> memory exhaustion in Request.ParseMultipartForm</li> <li> CVE-2024-24785 golang: html/template: errors returned from MarshalJSON methods may break template escaping</li> <li> CVE-2024-29041 express: cause malformed URLs to be evaluated [noo-1]</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3868?
The severity of RHSA-2024:3868 is classified as Important.
How do I fix RHSA-2024:3868?
To fix RHSA-2024:3868, you need to update your Red Hat Network Observability to the latest version.
What vulnerabilities are addressed in RHSA-2024:3868?
RHSA-2024:3868 addresses CVE-2024-29180 and CVE-2024-24786.
Is RHSA-2024:3868 applicable to all versions of Network Observability?
No, RHSA-2024:3868 is specifically applicable to Network Observability versions including 1.6.0.
What are the potential risks of not addressing RHSA-2024:3868?
Not addressing RHSA-2024:3868 may lead to file leaks and other security vulnerabilities in your network observability environment.