VDB
RHSA-2024%3A1812
RHSA-2024%3A1812
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the Golang net/http/internal package. This issue may allow a malicious user to send an HTTP request and cause the receiver to read more bytes from network than are in the body (up to 1GiB), causing the receiver to fail reading the response, possibly leading to a Denial of Service (DoS).
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64, *, custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:4c2b8009baf3e0424a3504f9bc49fc9342608fcd350afb2fbff2c9568e5f68da_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:4c2b8009baf3e0424a3504f9bc49fc9342608fcd350afb2fbff2c9568e5f68da_amd64, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:4c2b8009baf3e0424a3504f9bc49fc9342608fcd350afb2fbff2c9568e5f68da_amd64, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:4c2b8009baf3e0424a3504f9bc49fc9342608fcd350afb2fbff2c9568e5f68da_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8@sha256:902b54fc0dad9ceefa86752585e37788c47ae08423109b8c572966a56e29de18_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | *, *, custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8@sha256:902b54fc0dad9ceefa86752585e37788c47ae08423109b8c572966a56e29de18_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:4c2b8009baf3e0424a3504f9bc49fc9342608fcd350afb2fbff2c9568e5f68da_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | *, *, * |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | *, custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64, custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64, *, custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:4dd04c7c5b5fb1aeb50ac9cd52cce2b7be8eb69bddf460e98ee97849fddb1756_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64, custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64, custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:0352167d7c1b00293d9e855c37339f52b3f445a3b388ba0e95e813c5e3a40ddc_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8@sha256:af913191f4a7273f29545f64012cea08e2c35296d4e3e3b10c8358feb4c425bd_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8@sha256:af913191f4a7273f29545f64012cea08e2c35296d4e3e3b10c8358feb4c425bd_amd64, *, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8@sha256:af913191f4a7273f29545f64012cea08e2c35296d4e3e3b10c8358feb4c425bd_amd64 |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8@sha256:902b54fc0dad9ceefa86752585e37788c47ae08423109b8c572966a56e29de18_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | *, custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8@sha256:902b54fc0dad9ceefa86752585e37788c47ae08423109b8c572966a56e29de18_amd64, * |
| Red Hat | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8@sha256:af913191f4a7273f29545f64012cea08e2c35296d4e3e3b10c8358feb4c425bd_amd64 as a component of OpenShift Custom Metrics Autoscaler 2 | *, *, * |
Timeline
- Apr 15, 2024 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- May 15, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2024:1812 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/CVE-2024-28180 advisory
- https://access.redhat.com/security/cve/CVE-2023-47108 advisory
- https://access.redhat.com/security/cve/CVE-2023-39326 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2251198 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2253330 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2268854 issue
- https://issues.redhat.com/browse/OCPBUGS-25806 advisory
- https://issues.redhat.com/browse/OCPBUGS-30145 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1812.json advisory
- https://www.cve.org/CVERecord?id=CVE-2023-39326 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-39326 advisory
- https://pkg.go.dev/vuln/GO-2023-2382 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-47108 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-47108 advisory
- https://github.com/open-telemetry/opentelemetry-go-contrib/security/advisories/GHSA-8pgv-569h-w5rw advisory
- https://www.cve.org/CVERecord?id=CVE-2024-28180 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-28180 advisory
- https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g advisory