RHSA-2024:4057: Important: Release of OpenShift Serverless Logic 1.33.0 security update & enhancements
Important: Release of OpenShift Serverless Logic 1.33.0 security update & enhancements
Other sources
This release includes security, bug fixes, and enhancements.Security Fix(es): keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS (CVE-2024-1249) keycloak: XSS via assertion consumer service URL in SAML POST-binding flow (CVE-2023-6717) pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE (CVE-2024-1597) camel-core: Exposure of sensitive data by crafting a malicious EventFactory (CVE-2024-22371) commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file (CVE-2024-25710) commons-compress: OutOfMemoryError unpacking broken Pack200 file (CVE-2024-26308) jose4j: denial of service via specially crafted JWE (CVE-2023-51775) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4057?
The severity of RHSA-2024:4057 is rated as Important.
What software is affected by RHSA-2024:4057?
RHSA-2024:4057 affects Red Hat OpenShift Serverless, OpenShift Serverless for ARM, and OpenShift Serverless for IBM Power, little endian.
What vulnerabilities are addressed in RHSA-2024:4057?
RHSA-2024:4057 addresses unvalidated cross-origin messages in keycloak that could lead to a DDoS attack.
How do I fix RHSA-2024:4057?
To fix RHSA-2024:4057, update affected Red Hat OpenShift Serverless products to version 1.33.0 or later.
When was RHSA-2024:4057 released?
RHSA-2024:4057 was released to provide security updates and enhancements for OpenShift Serverless Logic.