VDB
RHSA-2024%3A10823
RHSA-2024%3A10823
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-cloud-credential-rhel9-operator@sha256:ca4ec6ff8c325f9ed28555bb56f43ffdc07b94617e9692fbebe6e2af0e4e243a_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-cloud-credential-rhel9-operator@sha256:ca4ec6ff8c325f9ed28555bb56f43ffdc07b94617e9692fbebe6e2af0e4e243a_arm64 |
| Red Hat | openshift4/ose-hypershift-rhel9@sha256:153b6d4ce73be9613c702afaa8774f4cb2ee539e08b3f12d751e64d516fcfacb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-hypershift-rhel9@sha256:153b6d4ce73be9613c702afaa8774f4cb2ee539e08b3f12d751e64d516fcfacb_ppc64le |
| Red Hat | openshift4/ose-installer-altinfra-rhel9@sha256:b671cd681c73903f8285012b8faeefbb7309676a0c9324b9f710a3793ce18918_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/driver-toolkit-rhel9@sha256:f789ae59040dd9708a37ea446d80da517fa0eb630ec4b3ff277353cee5c10287_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/driver-toolkit-rhel9@sha256:f789ae59040dd9708a37ea446d80da517fa0eb630ec4b3ff277353cee5c10287_s390x |
| Red Hat | openshift4/ose-cluster-autoscaler-rhel9@sha256:0044511738de69ba8ff84fd9b8b6beba2bea08020dce60b761166fa484657121_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-agent-installer-api-server-rhel9@sha256:c537893896ab4068ad183ebbae64d25c65645496aedda159ce9a4e41d6763eb0_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-cluster-autoscaler-rhel9@sha256:0d646b93c683b95943f7ee763097805579559e811f6c16cd71e9710e1bd8f78d_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-hypershift-rhel9@sha256:153b6d4ce73be9613c702afaa8774f4cb2ee539e08b3f12d751e64d516fcfacb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-cluster-autoscaler-rhel9@sha256:30547619975f84bbb85c0372a60e07ac548fdf68663943c6651caf458afffbbd_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-cluster-autoscaler-rhel9@sha256:30547619975f84bbb85c0372a60e07ac548fdf68663943c6651caf458afffbbd_ppc64le |
| Red Hat | openshift4/ose-baremetal-installer-rhel9@sha256:d3c56a54e7cbc934e19430b7e948e7b8a6f5d51b0918b3738e455f396427d4e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-installer-altinfra-rhel9@sha256:13daa8babcb0c4715ac0c23bb3c8b73cdc7d05e9e2e271b6355b1105b229e0e4_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-installer-altinfra-rhel9@sha256:b671cd681c73903f8285012b8faeefbb7309676a0c9324b9f710a3793ce18918_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-installer-altinfra-rhel9@sha256:b671cd681c73903f8285012b8faeefbb7309676a0c9324b9f710a3793ce18918_amd64 |
| Red Hat | openshift4/ose-tests-rhel9@sha256:965a17a70a8cae8db9131c35031ce15cadfb75a6ce54bd85c3ab48fc194f85f0_s390x as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:7387f761a9a58fa9507f723d97692ec576ad51da75b2d7bb49392a8caf8e9d2b_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | rhcos@sha256:cbb661edca8fcd254968a6f3838a385e5f9ab94b83b380fc4677c55c289952e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-cloud-credential-rhel9-operator@sha256:ae4ad261282bcaf0f49aaf964988675683739747e80046f964b8e41860a1990b_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-cluster-autoscaler-rhel9@sha256:0d646b93c683b95943f7ee763097805579559e811f6c16cd71e9710e1bd8f78d_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c77d180573859c703bc3e578eb7387d572e13fc08e4b3592d17b15d0ca0a4393_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:c77d180573859c703bc3e578eb7387d572e13fc08e4b3592d17b15d0ca0a4393_amd64 |
| Red Hat | openshift4/ose-cloud-credential-rhel9-operator@sha256:ca4ec6ff8c325f9ed28555bb56f43ffdc07b94617e9692fbebe6e2af0e4e243a_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-installer-altinfra-rhel9@sha256:9312cb8fd1e55f6b5055d8e2bd339cf1998bbdc5ce537ffb4c5a61b501f2f2aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-installer-altinfra-rhel9@sha256:9312cb8fd1e55f6b5055d8e2bd339cf1998bbdc5ce537ffb4c5a61b501f2f2aa_ppc64le |
…and 144 more
Timeline
- Dec 12, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:10823 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2324550 issue
- https://issues.redhat.com/browse/OCPBUGS-39372 advisory
- https://issues.redhat.com/browse/OCPBUGS-44456 advisory
- https://issues.redhat.com/browse/OCPBUGS-44792 advisory
- https://issues.redhat.com/browse/OCPBUGS-44874 advisory
- https://issues.redhat.com/browse/OCPBUGS-44875 advisory
- https://issues.redhat.com/browse/OCPBUGS-44895 advisory
- https://issues.redhat.com/browse/OCPBUGS-45015 advisory
- https://issues.redhat.com/browse/OCPBUGS-45124 advisory
- https://issues.redhat.com/browse/OCPBUGS-45181 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_10823.json advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://access.redhat.com/security/cve/CVE-2024-21538 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-21538 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-21538 advisory
…and 4 more