RHSA-2024:7726HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.6.2
🔗 CVE IDs covered (10)
📋 Description
CVE-2024-7264 — curl: libcurl: ASN.1 date parser overread
CVE-2024-43788 — webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule
CVE-2024-43796 — express: Improper Input Handling in Express Redirects
CVE-2024-43799 — send: Code Execution Vulnerability in Send Library
CVE-2024-43800 — serve-static: Improper Sanitization in serve-static
CVE-2024-45296 — path-to-regexp: Backtracking regular expressions cause ReDoS
CVE-2024-45590 — body-parser: Denial of Service Vulnerability in body-parser
CVE-2024-45806 — envoy: Potential to manipulate x-envoy headers from external sources
CVE-2024-45808 — envoy: Malicious log injection via access logs
CVE-2024-45810 — envoy: Envoy crashes for LocalReply in HTTP async client
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2024:7726
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2310908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311153
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2311171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313683
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313685
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2313687
- externalhttps://issues.redhat.com/browse/OSSM-3337
- externalhttps://issues.redhat.com/browse/OSSM-8001
- externalhttps://issues.redhat.com/browse/OSSM-8099
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7726.json