VDB
RHEA-2024:11005
RHEA-2024:11005
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the Node.js word-wrap module, where it is vulnerable to a denial of service caused by a Regular expression denial of service (ReDoS) issue in the result variable. By sending a specially crafted regex input, a remote attacker can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-gitops-1/gitops-rhel8-operator@sha256:50b0ad92d0ac591ce1f771f085127a49e77da9194be3090f507d1087e5e7370c_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8-operator@sha256:50b0ad92d0ac591ce1f771f085127a49e77da9194be3090f507d1087e5e7370c_arm64 |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:3db8ac8dbf1d7903e8c4092252e4304613d9db355c023d44c543744e6f79543c_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:3db8ac8dbf1d7903e8c4092252e4304613d9db355c023d44c543744e6f79543c_s390x |
| Red Hat | openshift-gitops-1/argo-rollouts-rhel8@sha256:bb127cf71b12a2c609472d11f8a7abebd9b3f7e4d97b0c3bf6a7fb1feb495ff5_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argo-rollouts-rhel8@sha256:bb127cf71b12a2c609472d11f8a7abebd9b3f7e4d97b0c3bf6a7fb1feb495ff5_arm64 |
| Red Hat | openshift-gitops-1/argo-rollouts-rhel8@sha256:4de7f6f1dd2f4acd724bef944edf93479436062b38d78c1be4d6c2ae79be51ab_s390x as a component of Red Hat OpenShift GitOps 1.15 | * |
| Red Hat | openshift-gitops-1/argo-rollouts-rhel8@sha256:ab092a4f6dd463eeab4023ab8a205f55934114b5a599f3b12f6517b2f34068a3_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argo-rollouts-rhel8@sha256:ab092a4f6dd463eeab4023ab8a205f55934114b5a599f3b12f6517b2f34068a3_amd64 |
| Red Hat | openshift-gitops-1/gitops-rhel8-operator@sha256:4930bd0b3e1f2afd467bf427935f480e5c44b186b3ffefed0067bd06c38f2563_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8-operator@sha256:4930bd0b3e1f2afd467bf427935f480e5c44b186b3ffefed0067bd06c38f2563_ppc64le |
| Red Hat | openshift-gitops-1/gitops-rhel8-operator@sha256:8367550eceb7b5b836aa49aeec60332fdd4bb9d02f65c6af978e2b2978e229cc_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8-operator@sha256:8367550eceb7b5b836aa49aeec60332fdd4bb9d02f65c6af978e2b2978e229cc_amd64 |
| Red Hat | openshift-gitops-1/must-gather-rhel8@sha256:596acc8089c28cbd4dabce1b4f98d5c644b8a6ee262e94e64139b408c9ee21c3_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/must-gather-rhel8@sha256:596acc8089c28cbd4dabce1b4f98d5c644b8a6ee262e94e64139b408c9ee21c3_ppc64le |
| Red Hat | openshift-gitops-1/argocd-extensions-rhel8@sha256:54f037404864fb017b0fe7a051d12fba02df6c3a335931517b42f9d07978c0d0_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-extensions-rhel8@sha256:54f037404864fb017b0fe7a051d12fba02df6c3a335931517b42f9d07978c0d0_ppc64le |
| Red Hat | openshift-gitops-1/gitops-rhel8@sha256:1f2e2aaa17a7ef1056723111a009cc80278e006475b1a2488bb672df055445d4_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-rhel8@sha256:1f2e2aaa17a7ef1056723111a009cc80278e006475b1a2488bb672df055445d4_arm64 |
| Red Hat | openshift-gitops-1/argocd-rhel9@sha256:c3f691017ec263cbe63aa7cfbd4a0ce7e44c7c1f9cbcbd2ff1cb7633e4027cd5_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/argocd-rhel9@sha256:c3f691017ec263cbe63aa7cfbd4a0ce7e44c7c1f9cbcbd2ff1cb7633e4027cd5_arm64 |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:d2e7896e0152315b9aa79a079e6a9ee25db9862edc3c10fdc4efa2c4664bee8d_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:d2e7896e0152315b9aa79a079e6a9ee25db9862edc3c10fdc4efa2c4664bee8d_ppc64le |
| Red Hat | openshift-gitops-1/argocd-rhel8@sha256:79c6977dee09396b796fe8822ac8abf6ed6cfa6bb4bd96b5468b52c297be2fbc_arm64 as a component of Red Hat OpenShift GitOps 1.15 | * |
| Red Hat | openshift-gitops-1/console-plugin-rhel8@sha256:ed6abcf7aef6f9f2e8e82ee657717bce98e0ab6d6a72fc9822c16ae80a26ec5c_arm64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/console-plugin-rhel8@sha256:ed6abcf7aef6f9f2e8e82ee657717bce98e0ab6d6a72fc9822c16ae80a26ec5c_arm64 |
| Red Hat | openshift-gitops-1/dex-rhel8@sha256:882b41b4a4b6dc78de877d55bac02b47cf9cd8dfea66679d79f8c3b07c37f5b5_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/dex-rhel8@sha256:882b41b4a4b6dc78de877d55bac02b47cf9cd8dfea66679d79f8c3b07c37f5b5_amd64 |
| Red Hat | openshift-gitops-1/argocd-rhel8@sha256:4eb18b2e388479bd9502dbb88f2efb7f95ccbad09c7f34bcb708c70e4c0792fc_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | * |
| Red Hat | openshift-gitops-1/argocd-rhel9@sha256:ccb7977d8394c72606a76ed614226cd55b43bd3e3070db05597836f17b0d0e9b_amd64 as a component of Red Hat OpenShift GitOps 1.15 | * |
| Red Hat | openshift-gitops-1/must-gather-rhel8@sha256:667f72e5f2ca3b0db841cfadd6ffe5aad7456324897f9ded011ec3cf1e8684f0_s390x as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/must-gather-rhel8@sha256:667f72e5f2ca3b0db841cfadd6ffe5aad7456324897f9ded011ec3cf1e8684f0_s390x |
| Red Hat | openshift-gitops-1/gitops-operator-bundle@sha256:c605145a2b2454c969e43b5d8390d29c932bb0eeb4ba2eb9f0c72d8c909ae8cb_amd64 as a component of Red Hat OpenShift GitOps 1.15 | openshift-gitops-1/gitops-operator-bundle@sha256:c605145a2b2454c969e43b5d8390d29c932bb0eeb4ba2eb9f0c72d8c909ae8cb_amd64 |
| Red Hat | openshift-gitops-1/argo-rollouts-rhel8@sha256:e00bf0968b232c2b191cb54559718282df0e98d7b8588d46c78e876ab872f502_ppc64le as a component of Red Hat OpenShift GitOps 1.15 | * |
…and 15 more
Timeline
- Dec 12, 2024 CVE Published
- Apr 30, 2026 CVE Updated
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHEA-2024:11005 advisory
- https://issues.redhat.com/browse/GITOPS-2654 advisory
- https://issues.redhat.com/browse/GITOPS-3501 advisory
- https://issues.redhat.com/browse/GITOPS-3604 advisory
- https://issues.redhat.com/browse/GITOPS-3987 advisory
- https://issues.redhat.com/browse/GITOPS-4175 advisory
- https://issues.redhat.com/browse/GITOPS-4217 advisory
- https://issues.redhat.com/browse/GITOPS-5220 advisory
- https://issues.redhat.com/browse/GITOPS-5221 advisory
- https://issues.redhat.com/browse/GITOPS-5385 advisory
- https://issues.redhat.com/browse/GITOPS-5386 advisory
- https://issues.redhat.com/browse/GITOPS-5388 advisory
- https://issues.redhat.com/browse/GITOPS-5395 advisory
- https://issues.redhat.com/browse/GITOPS-5622 advisory
- https://issues.redhat.com/browse/GITOPS-5660 advisory
- https://issues.redhat.com/browse/GITOPS-5661 advisory
- https://issues.redhat.com/browse/GITOPS-5674 advisory
- https://issues.redhat.com/browse/GITOPS-5739 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhea-2024_11005.json advisory
- https://access.redhat.com/security/cve/CVE-2023-26115 advisory
…and 3 more