VDB

RHSA-2024%3A3331

RHSA-2024%3A3331 PUBLISHED CVSS 7.5 HIGH

A vulnerability was discovered with the implementation of the HTTP/2 protocol in the Go programming language. There were insufficient limitations on the amount of CONTINUATION frames sent within a single stream. An attacker could potentially exploit this to cause a Denial of Service (DoS) attack.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-console@sha256:3cfd3e8f7e91da7ea25fc3e0f142dc34ef43165ddc724203bae26a8967041b41_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-console@sha256:3cfd3e8f7e91da7ea25fc3e0f142dc34ef43165ddc724203bae26a8967041b41_amd64
Red Hatopenshift4/ose-pod@sha256:0f6ec1e4ec9138491cd9c6b49038c49eabc1e9116a25e5be6ddc709a36339383_amd64 as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-installer@sha256:5e5b08bdfcd33d89cf57a4efdb7aab9c9dda994f82221566ddaae76f54c8fb11_s390x as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-installer@sha256:7ebbce099af34c40bba4dac1daa07ef734374294b3ac3b31b48d8890c2bedbd5_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-installer@sha256:7ebbce099af34c40bba4dac1daa07ef734374294b3ac3b31b48d8890c2bedbd5_ppc64le
Red Hatopenshift4/ose-installer@sha256:dde17bfcd61fbed0cbe7764c6c827d79f7e4f5161f7182dbdf8044ce3ae00d71_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-installer@sha256:dde17bfcd61fbed0cbe7764c6c827d79f7e4f5161f7182dbdf8044ce3ae00d71_arm64
Red Hatopenshift4/ose-cluster-autoscaler-operator@sha256:ad18da2c0f3bbcf912d3fe0cba164cf0365120841ec67fa8c79945eb0694432b_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-autoscaler-operator@sha256:ad18da2c0f3bbcf912d3fe0cba164cf0365120841ec67fa8c79945eb0694432b_amd64
Red Hatopenshift4/ose-agent-installer-utils-rhel9@sha256:c294d0e0a08c16b1ec0a2fca681c2e95a95e5a2fbdd73d866ca006fe65225c99_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-agent-installer-utils-rhel9@sha256:c294d0e0a08c16b1ec0a2fca681c2e95a95e5a2fbdd73d866ca006fe65225c99_amd64
Red Hatopenshift4/ose-haproxy-router@sha256:7d2c004c7567b0203ac9eb16b06971b0e0e36986ab09da7e90f80db6815866c6_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-haproxy-router@sha256:7d2c004c7567b0203ac9eb16b06971b0e0e36986ab09da7e90f80db6815866c6_s390x
Red Hatopenshift4/ose-hyperkube-rhel9@sha256:bc093a8ded0afe2024a90acd6ef0e1a20c717eabfc80c08e585f823cd10327ea_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-hyperkube-rhel9@sha256:bc093a8ded0afe2024a90acd6ef0e1a20c717eabfc80c08e585f823cd10327ea_amd64
Red Hatopenshift4/ose-machine-api-operator@sha256:7525f7f7ed6372b8ae82da56e4cd6f90be5019ef88024f3f9f4d9a286f095ea3_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-machine-api-operator@sha256:7525f7f7ed6372b8ae82da56e4cd6f90be5019ef88024f3f9f4d9a286f095ea3_amd64
Red Hatopenshift4/ose-ironic-rhel9@sha256:c8c0b9ae7c1988326b812eec034e9065cd305ae6a927cd81138e3687ef45ec38_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-ironic-rhel9@sha256:c8c0b9ae7c1988326b812eec034e9065cd305ae6a927cd81138e3687ef45ec38_arm64
Red Hatopenshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:99dee0b732d4f8970eab77c13d825914d1e223822a4d132fa47c78678c8dad09_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:99dee0b732d4f8970eab77c13d825914d1e223822a4d132fa47c78678c8dad09_ppc64le
Red Hatopenshift4/ose-etcd-rhel9@sha256:1b12181214ad990931de365eecb7efe4ab34a3147cdafcc296298d35a4f7d83a_arm64 as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-cluster-node-tuning-operator@sha256:be407bccfcbdaa82015c867efb9b038d3c14770bcebc4636d889f41afe65914e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-baremetal-installer-rhel8@sha256:ddc445eeee2bf0ae040b83ef0a098854821216be3b1a08a497561ae53bdd6581_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-baremetal-installer-rhel8@sha256:ddc445eeee2bf0ae040b83ef0a098854821216be3b1a08a497561ae53bdd6581_amd64
Red Hatopenshift4/ose-cluster-node-tuning-rhel9-operator@sha256:50a34f4cdb25748514ca688375bfc4ef3ed379818243214e62dd3360be44aa71_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:50a34f4cdb25748514ca688375bfc4ef3ed379818243214e62dd3360be44aa71_arm64
Red Hatopenshift4/ose-ovn-kubernetes@sha256:6873d858751a440eb7d159e0743b8a6e66e40de20eb6a6532cedcaa2cc451dac_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-ovn-kubernetes@sha256:6873d858751a440eb7d159e0743b8a6e66e40de20eb6a6532cedcaa2cc451dac_s390x
Red Hatopenshift4/ose-cluster-autoscaler-operator@sha256:f93a29b2665dd9423966162461c32756322c44b01c358ff3eacc57fb0f7a0048_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-autoscaler-operator@sha256:f93a29b2665dd9423966162461c32756322c44b01c358ff3eacc57fb0f7a0048_s390x
Red Hatopenshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:d648d2d83769d09a3c15a189dd7c3ea66c81365b9944a1d28da3707c38de39c0_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-ovn-kubernetes-microshift-rhel9@sha256:d648d2d83769d09a3c15a189dd7c3ea66c81365b9944a1d28da3707c38de39c0_s390x
Red Hatopenshift4/ose-baremetal-installer-rhel8@sha256:d81bedd24ef68bab60a00620923a02ed9666ee3089ea175624524c2af29f4502_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-baremetal-installer-rhel8@sha256:d81bedd24ef68bab60a00620923a02ed9666ee3089ea175624524c2af29f4502_arm64

…and 78 more

Timeline

  • May 30, 2024 CVE Published
  • Apr 25, 2026 CVE Updated
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›