First published: Wed Jul 10 2024(Updated: )
OpenShift Virtualization is Red Hat's virtualization solution designed for Red Hat OpenShift Container Platform.<br>This advisory contains OpenShift Virtualization 4.16.0 images.<br>Security Fix(es):<br><li> axios: exposure of confidential data stored in cookies (CVE-2023-45857)</li> <li> golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)</li> <li> jose-go: improper handling of highly compressed data (CVE-2024-28180)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Virtualization |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:4455 is high due to the exposure of confidential data stored in cookies.
To fix RHSA-2024:4455, update your OpenShift Virtualization to version 4.16.0 or later.
RHSA-2024:4455 affects the Red Hat OpenShift Virtualization solution.
RHSA-2024:4455 addresses the vulnerability associated with CVE-2023-45857.
There are no recommended workarounds for RHSA-2024:4455 other than applying the security update.