VDB
RHSA-2024%3A10813
RHSA-2024%3A10813
PUBLISHED
CVSS 7.300000190734863 HIGH
A flaw was found in Gin-Gonic Gin. This flaw allows a remote attacker to bypass security restrictions caused by improper input validation. An attacker can perform cache poisoning attacks by sending a specially-crafted request using the X-Forwarded-Prefix header.
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-prometheus@sha256:2a9e58f2fa0681d4f8c24cc322ad6b4138b55c915b5f3833866e97992287c71c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-prometheus@sha256:2a9e58f2fa0681d4f8c24cc322ad6b4138b55c915b5f3833866e97992287c71c_amd64, *, openshift4/ose-prometheus@sha256:2a9e58f2fa0681d4f8c24cc322ad6b4138b55c915b5f3833866e97992287c71c_amd64 |
| Red Hat | openshift4/ose-cluster-bootstrap@sha256:9f0ac692e26d470b88a5ff29ee51b7cb53e1bca060a942f30df68c1cff7dd09c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-bootstrap@sha256:9f0ac692e26d470b88a5ff29ee51b7cb53e1bca060a942f30df68c1cff7dd09c_amd64, openshift4/ose-cluster-bootstrap@sha256:9f0ac692e26d470b88a5ff29ee51b7cb53e1bca060a942f30df68c1cff7dd09c_amd64, * |
| Red Hat | openshift4/ose-csi-driver-nfs-rhel8@sha256:09c47351b6cde2dff1d398fc6f736e5be70ea95b2b985255941510b8b745db4b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-csi-driver-nfs-rhel8@sha256:09c47351b6cde2dff1d398fc6f736e5be70ea95b2b985255941510b8b745db4b_amd64, openshift4/ose-csi-driver-nfs-rhel8@sha256:09c47351b6cde2dff1d398fc6f736e5be70ea95b2b985255941510b8b745db4b_amd64, openshift4/ose-csi-driver-nfs-rhel8@sha256:09c47351b6cde2dff1d398fc6f736e5be70ea95b2b985255941510b8b745db4b_amd64 |
| Red Hat | openshift4/ose-thanos-rhel8@sha256:8f6c79108f3d0908c8663f6fc2d132b115130a3772b24eca29f90de030bcfaac_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-thanos-rhel8@sha256:8f6c79108f3d0908c8663f6fc2d132b115130a3772b24eca29f90de030bcfaac_amd64, *, * |
| Red Hat | openshift4/ose-oauth-proxy@sha256:4aee098861080f307e69b0f7ef7a7e5ddc12ec0a674750945d4ee30d02feb29b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, openshift4/ose-oauth-proxy@sha256:4aee098861080f307e69b0f7ef7a7e5ddc12ec0a674750945d4ee30d02feb29b_amd64 |
| Red Hat | openshift4/ose-vsphere-cluster-api-controllers-rhel8@sha256:e210a5c5e7ebda196a8745aa5cc3e01c081675c35337bcd62c26145800609ebc_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-ironic-agent-rhel9@sha256:45723857a9d76af1524294f1780ebc021c149e909ee77004e4959367a307082e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/ose-ironic-agent-rhel9@sha256:45723857a9d76af1524294f1780ebc021c149e909ee77004e4959367a307082e_amd64, openshift4/ose-ironic-agent-rhel9@sha256:45723857a9d76af1524294f1780ebc021c149e909ee77004e4959367a307082e_amd64 |
| Red Hat | openshift4/ose-csi-driver-shared-resource-rhel8@sha256:369d55382b154d7d002844d43f3e80b57dcc3456dbb182347ad1f2cfae05320e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-csi-driver-shared-resource-rhel8@sha256:369d55382b154d7d002844d43f3e80b57dcc3456dbb182347ad1f2cfae05320e_amd64, openshift4/ose-csi-driver-shared-resource-rhel8@sha256:369d55382b154d7d002844d43f3e80b57dcc3456dbb182347ad1f2cfae05320e_amd64, * |
| Red Hat | openshift4/ose-cluster-autoscaler-operator@sha256:f4152f66fd54415243266083dcf950a97938ee76bd54fa75d6a3fb925f25b7fb_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-autoscaler-operator@sha256:f4152f66fd54415243266083dcf950a97938ee76bd54fa75d6a3fb925f25b7fb_amd64, *, * |
| Red Hat | openshift4/ose-csi-external-snapshotter@sha256:54a64252afee1c4a7c547153d36e559343a648d3a9264c06faee3da95968d594_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-csi-external-snapshotter@sha256:54a64252afee1c4a7c547153d36e559343a648d3a9264c06faee3da95968d594_amd64, openshift4/ose-csi-external-snapshotter@sha256:54a64252afee1c4a7c547153d36e559343a648d3a9264c06faee3da95968d594_amd64, openshift4/ose-csi-external-snapshotter@sha256:54a64252afee1c4a7c547153d36e559343a648d3a9264c06faee3da95968d594_amd64 |
| Red Hat | openshift4/ose-cluster-config-operator@sha256:a9930a178db0c40cf9286288aa0f3592e3732f2d06aa41afc005efbf2bf2f909_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-config-operator@sha256:a9930a178db0c40cf9286288aa0f3592e3732f2d06aa41afc005efbf2bf2f909_amd64, openshift4/ose-cluster-config-operator@sha256:a9930a178db0c40cf9286288aa0f3592e3732f2d06aa41afc005efbf2bf2f909_amd64, openshift4/ose-cluster-config-operator@sha256:a9930a178db0c40cf9286288aa0f3592e3732f2d06aa41afc005efbf2bf2f909_amd64 |
| Red Hat | openshift4/ose-kubevirt-cloud-controller-manager-rhel8@sha256:8c4beab1fd1a41648cfb32a93d523bba1d6e724b01738beb95a98cf75473aa1f_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-kubevirt-cloud-controller-manager-rhel8@sha256:8c4beab1fd1a41648cfb32a93d523bba1d6e724b01738beb95a98cf75473aa1f_amd64, openshift4/ose-kubevirt-cloud-controller-manager-rhel8@sha256:8c4beab1fd1a41648cfb32a93d523bba1d6e724b01738beb95a98cf75473aa1f_amd64, * |
| Red Hat | openshift4/ose-nutanix-machine-controllers-rhel8@sha256:2c9140ecec6a33150fcba4e3ce45ab375efbdbc5d4586e83b813c3f794343514_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-cli@sha256:f6f79c45ec44f4d7097d2966f79bc648e6788c0ecf3710a44cbc46f00ebdeb1d_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, openshift4/ose-cli@sha256:f6f79c45ec44f4d7097d2966f79bc648e6788c0ecf3710a44cbc46f00ebdeb1d_amd64 |
| Red Hat | openshift4/ose-cluster-policy-controller-rhel8@sha256:67a10c1105dc9615ca14a4c71cb9da81f4763475162bdfcfee88ea5e72c6c848_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/ose-cluster-policy-controller-rhel8@sha256:67a10c1105dc9615ca14a4c71cb9da81f4763475162bdfcfee88ea5e72c6c848_amd64, openshift4/ose-cluster-policy-controller-rhel8@sha256:67a10c1105dc9615ca14a4c71cb9da81f4763475162bdfcfee88ea5e72c6c848_amd64 |
| Red Hat | openshift4/ose-machine-api-operator@sha256:a3a615de885e2c43d38d4fe5924c06b2187daf1fe4e2133e089ce9c0f1e4698c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-machine-api-operator@sha256:a3a615de885e2c43d38d4fe5924c06b2187daf1fe4e2133e089ce9c0f1e4698c_amd64, *, openshift4/ose-machine-api-operator@sha256:a3a615de885e2c43d38d4fe5924c06b2187daf1fe4e2133e089ce9c0f1e4698c_amd64 |
| Red Hat | openshift4/ose-agent-installer-csr-approver-rhel8@sha256:03f3f96fe2a567313d71d58240ef98d2aab836c454349e52d01dd766a4e65784_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-agent-installer-csr-approver-rhel8@sha256:03f3f96fe2a567313d71d58240ef98d2aab836c454349e52d01dd766a4e65784_amd64, openshift4/ose-agent-installer-csr-approver-rhel8@sha256:03f3f96fe2a567313d71d58240ef98d2aab836c454349e52d01dd766a4e65784_amd64, openshift4/ose-agent-installer-csr-approver-rhel8@sha256:03f3f96fe2a567313d71d58240ef98d2aab836c454349e52d01dd766a4e65784_amd64 |
| Red Hat | openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:30e01ac8da19f0e709d0d8b475179ae597b9c4dd29354a4f848d77f7daa9f0b6_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:30e01ac8da19f0e709d0d8b475179ae597b9c4dd29354a4f848d77f7daa9f0b6_amd64, openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:30e01ac8da19f0e709d0d8b475179ae597b9c4dd29354a4f848d77f7daa9f0b6_amd64, openshift4/ose-cluster-control-plane-machine-set-operator-rhel8@sha256:30e01ac8da19f0e709d0d8b475179ae597b9c4dd29354a4f848d77f7daa9f0b6_amd64 |
| Red Hat | openshift4/ose-vmware-vsphere-csi-driver-rhel8@sha256:210554e50580f7392c710658f9ee29023a3d40a2b85ec0f7963beebb22114c83_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-vmware-vsphere-csi-driver-rhel8@sha256:210554e50580f7392c710658f9ee29023a3d40a2b85ec0f7963beebb22114c83_amd64, openshift4/ose-vmware-vsphere-csi-driver-rhel8@sha256:210554e50580f7392c710658f9ee29023a3d40a2b85ec0f7963beebb22114c83_amd64, * |
| Red Hat | openshift4/ose-must-gather@sha256:1a3e128db74439804f2ed0e917e12a7e2a21596014c707fdd0f4604fc914fd1c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-must-gather@sha256:1a3e128db74439804f2ed0e917e12a7e2a21596014c707fdd0f4604fc914fd1c_amd64, *, openshift4/ose-must-gather@sha256:1a3e128db74439804f2ed0e917e12a7e2a21596014c707fdd0f4604fc914fd1c_amd64 |
…and 366 more
Timeline
- Dec 12, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:10813 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2023-003 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2203769 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2243296 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2295777 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2302487 issue
- https://issues.redhat.com/browse/OCPBUGS-42951 advisory
- https://issues.redhat.com/browse/OCPBUGS-43886 advisory
- https://issues.redhat.com/browse/OCPBUGS-44206 advisory
- https://issues.redhat.com/browse/OCPBUGS-44585 advisory
- https://issues.redhat.com/browse/OCPBUGS-44692 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10813.json advisory
- https://access.redhat.com/security/cve/CVE-2023-26125 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-26125 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-26125 advisory
- https://www.postgresql.org/support/security/CVE-2023-2454/ advisory
- https://access.redhat.com/security/cve/CVE-2023-39325 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39325 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39325 advisory
…and 10 more