RHSA-2024:8023: Important: Release of OpenShift Serverless Logic 1.34.0 security update & enhancements
Important: Release of OpenShift Serverless Logic 1.34.0 security update & enhancements
Other sources
This release includes security, bug fixes, and enhancements.Security Fix(es): axios: axios: Server-Side Request Forgery (CVE-2024-39338) express: Improper Input Handling in Express Redirects (CVE-2024-43796) io.vertx/vertx-grpc-client: Vertx gRPC server does not limit the maximum message size (CVE-2024-8391) io.vertx/vertx-grpc-server: Vertx gRPC server does not limit the maximum message size (CVE-2024-8391) send: Code Execution Vulnerability in Send Library (CVE-2024-43799) serve-static: Improper Sanitization in serve-static (CVE-2024-43800) webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8023?
RHSA-2024:8023 has been classified as an important security update.
How do I fix RHSA-2024:8023?
To fix RHSA-2024:8023, you should update your OpenShift Serverless deployment to version 1.34.0 or later.
What vulnerabilities are addressed in RHSA-2024:8023?
RHSA-2024:8023 addresses Server-Side Request Forgery in axios (CVE-2024-39338) and improper input handling in express.
Which products are affected by RHSA-2024:8023?
RHSA-2024:8023 affects Red Hat OpenShift Serverless, Red Hat OpenShift Serverless for ARM, and Red Hat OpenShift Serverless for IBM Power, little endian.
What should I do if I cannot update due to compatibility issues with RHSA-2024:8023?
If you cannot update due to compatibility issues, it is recommended to assess the risk and explore temporary mitigations while planning for an eventual update.