VDB
RHEA-2024%3A7870
RHEA-2024%3A7870
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in ISAACS's node-tar, where it is vulnerable to a denial of service, caused by the lack of folder count validation. The vulnerability exists due to the application not properly controlling the consumption of internal resources while parsing a tar file. By sending a specially crafted request, a remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-pipelines/pipelines-results-api-rhel8@sha256:bfbbccf02f9dbcbb0504188ba88605391e5e1ff5f09a8ba254867f74cf2385ff_arm64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-results-api-rhel8@sha256:bfbbccf02f9dbcbb0504188ba88605391e5e1ff5f09a8ba254867f74cf2385ff_arm64 |
| Red Hat | openshift-pipelines/pipelines-triggers-controller-rhel8@sha256:3f9fa2c6058da4836d92fea2405296de1ed900179a60fd07ed14b9ae1705fdea_amd64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-triggers-controller-rhel8@sha256:3f9fa2c6058da4836d92fea2405296de1ed900179a60fd07ed14b9ae1705fdea_amd64 |
| Red Hat | openshift-pipelines/pipelines-triggers-eventlistenersink-rhel8@sha256:b9a1f7c7625bfbf00137ad61d9995f3530fc8a513558370b4b7a3e37b22fc9c0_s390x as a component of OpenShift Pipelines version 1.16 for RHEL 8 | * |
| Red Hat | openshift-pipelines/pipelines-results-api-rhel8@sha256:035e9b78ad832f30f15d9b75f7ae2faf220fe7d54b0cafcb184e242f77148a7b_s390x as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-results-api-rhel8@sha256:035e9b78ad832f30f15d9b75f7ae2faf220fe7d54b0cafcb184e242f77148a7b_s390x |
| Red Hat | openshift-pipelines/pipelines-hub-ui-rhel8@sha256:940208d4dd7b2d9700afde7071d4a17a428c1986b25294e4795f15ff90155cfb_arm64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | * |
| Red Hat | openshift-pipelines/pipelines-hub-db-migration-rhel8@sha256:4fa64c0356d5de6ba506f6e5fe0af5112a071407f7882a4b69624d77e20014f5_amd64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | * |
| Red Hat | openshift-pipelines/pipelines-operator-proxy-rhel8@sha256:6b79cc81807a4ba2eb1170d4c4341d4b3ec92b4e94c5de9837596bb082cc5628_amd64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-operator-proxy-rhel8@sha256:6b79cc81807a4ba2eb1170d4c4341d4b3ec92b4e94c5de9837596bb082cc5628_amd64 |
| Red Hat | openshift-pipelines/pipelines-hub-api-rhel8@sha256:38df2ee7b5531f7d2539a9b43cb4dee79c9afc3c47a9acd7a53352381bc77e0c_amd64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-hub-api-rhel8@sha256:38df2ee7b5531f7d2539a9b43cb4dee79c9afc3c47a9acd7a53352381bc77e0c_amd64 |
| Red Hat | openshift-pipelines/pipelines-controller-rhel8@sha256:a1e781866d3c356f38e89a3937d6b96a3c15b7b880f1a5c35fe7e106f81213fe_amd64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | * |
| Red Hat | openshift-pipelines/pipelines-results-retention-policy-agent-rhel8@sha256:4358bd5264994f7e2fefce583da0714fb9d4fb085eb1ab51b8309f0d94b9f153_s390x as a component of OpenShift Pipelines version 1.16 for RHEL 8 | * |
| Red Hat | openshift-pipelines/pipelines-triggers-webhook-rhel8@sha256:86c090b24787fd0ffd1a17317743dcda4c7a5f37e62bc4772b1db7d71b547ff8_ppc64le as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-triggers-webhook-rhel8@sha256:86c090b24787fd0ffd1a17317743dcda4c7a5f37e62bc4772b1db7d71b547ff8_ppc64le |
| Red Hat | openshift-pipelines/pipelines-results-retention-policy-agent-rhel8@sha256:a07c342c2e0cb85ab07527dd943cabfaac076ca3d541a94046fdaea882a1c627_ppc64le as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-results-retention-policy-agent-rhel8@sha256:a07c342c2e0cb85ab07527dd943cabfaac076ca3d541a94046fdaea882a1c627_ppc64le |
| Red Hat | openshift-pipelines/pipelines-results-api-rhel8@sha256:1526233c99e74ac377c7c4c0b632a3755e468c9566b868330860ecf7bebac73c_ppc64le as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-results-api-rhel8@sha256:1526233c99e74ac377c7c4c0b632a3755e468c9566b868330860ecf7bebac73c_ppc64le |
| Red Hat | openshift-pipelines/pipelines-controller-rhel8@sha256:93e0a7bcbef2432c645a0f7295035776950ff2018452b6a63bdd3af9312746c3_arm64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-controller-rhel8@sha256:93e0a7bcbef2432c645a0f7295035776950ff2018452b6a63bdd3af9312746c3_arm64 |
| Red Hat | openshift-pipelines/pipelines-resolvers-rhel8@sha256:d67ae06f23f7325531799ccef39d69c2967d0dae7bf7be560e65b02f0e1632a0_ppc64le as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-resolvers-rhel8@sha256:d67ae06f23f7325531799ccef39d69c2967d0dae7bf7be560e65b02f0e1632a0_ppc64le |
| Red Hat | openshift-pipelines/pipelines-hub-ui-rhel8@sha256:331d6aa12b6dbe31110d4df4167150dc113b5915be1ffbbd8b606070c487b5ad_ppc64le as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-hub-ui-rhel8@sha256:331d6aa12b6dbe31110d4df4167150dc113b5915be1ffbbd8b606070c487b5ad_ppc64le |
| Red Hat | openshift-pipelines/pipelines-results-api-rhel8@sha256:bfbbccf02f9dbcbb0504188ba88605391e5e1ff5f09a8ba254867f74cf2385ff_arm64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-results-api-rhel8@sha256:bfbbccf02f9dbcbb0504188ba88605391e5e1ff5f09a8ba254867f74cf2385ff_arm64 |
| Red Hat | openshift-pipelines/pipelines-serve-tkn-cli-rhel8@sha256:d0923360f8d0b918fe45fd89a0bccfb5066daa40a898aee8e5848cbfbab3a168_amd64 as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-serve-tkn-cli-rhel8@sha256:d0923360f8d0b918fe45fd89a0bccfb5066daa40a898aee8e5848cbfbab3a168_amd64 |
| Red Hat | openshift-pipelines/pipelines-triggers-webhook-rhel8@sha256:38d1eb001acb51af95e7f4a1878ae55818b1b9863a94c8e4b03e88ea4db2c5a0_s390x as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-triggers-webhook-rhel8@sha256:38d1eb001acb51af95e7f4a1878ae55818b1b9863a94c8e4b03e88ea4db2c5a0_s390x |
| Red Hat | openshift-pipelines/pipelines-results-watcher-rhel8@sha256:31f797b35537f16b4da2dabcc6fa8403540f2fa4fd2fb4756cc761db7d835eae_ppc64le as a component of OpenShift Pipelines version 1.16 for RHEL 8 | openshift-pipelines/pipelines-results-watcher-rhel8@sha256:31f797b35537f16b4da2dabcc6fa8403540f2fa4fd2fb4756cc761db7d835eae_ppc64le |
…and 204 more
Timeline
- Oct 9, 2024 CVE Published
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
- May 2, 2026 Security Advisory
References
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhea-2024_7870.json advisory
- https://www.cve.org/CVERecord?id=CVE-2024-28863 advisory
- https://security.netapp.com/advisory/ntap-20240524-0005/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2290901 issue
- https://www.cve.org/CVERecord?id=CVE-2024-29041 advisory
- https://github.com/expressjs/express/commit/0b746953c4bd8e377123527db11f9cd866e39f94 advisory
- https://github.com/expressjs/express/pull/5539 advisory
- https://github.com/expressjs/express/security/advisories/GHSA-rv95-896h-c2vc advisory
- https://access.redhat.com/security/cve/CVE-2024-29180 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-29180 advisory
- https://github.com/webpack/webpack-dev-middleware/security/advisories/GHSA-wr3j-pwj9-hqq6 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2304369 issue
- https://nvd.nist.gov/vuln/detail/CVE-2024-39338 advisory
- https://github.com/axios/axios/releases advisory
- https://jeffhacks.com/advisories/2024/06/24/CVE-2024-39338.html advisory
- https://access.redhat.com/errata/RHEA-2024:7870 advisory
- https://docs.openshift.com/container-platform/4.14/cicd/pipelines/understanding-openshift-pipelines.html advisory
- https://issues.redhat.com/browse/SRVKP-3933 advisory
- https://access.redhat.com/security/cve/CVE-2024-28863 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2293200 issue
…and 11 more