VDB

RHSA-2024%3A4316

RHSA-2024%3A4316 PUBLISHED CVSS 6 MEDIUM

A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.

Risk Scores

CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-cluster-csi-snapshot-controller-rhel9-operator@sha256:82d4fa29a406dbd999d190bf873573ce13973ab46f9f7b0ca84ff3fbfd2a8696_arm64 as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-multus-networkpolicy-rhel9@sha256:1a46ba36baeaf8016a4e79f53d7209875f2211d8b5d391919a9cb2547e03cbd4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-multus-networkpolicy-rhel9@sha256:1a46ba36baeaf8016a4e79f53d7209875f2211d8b5d391919a9cb2547e03cbd4_ppc64le
Red Hatopenshift4/kube-metrics-server-rhel9@sha256:78d93f684563e7cc5a7fd8e335f3b2de62df46f4f50b06729a7102259585da1c_amd64 as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-must-gather-rhel9@sha256:a29a7f6bd08ecfc03a3e156c82d521fa8209307d08036beefdbe777d8453c0aa_s390x as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-csi-external-provisioner-rhel9@sha256:b599b46bf16ddc7bb28c350520b3e6492f30e947904d0ac35970f999a76acd26_ppc64le as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-openshift-controller-manager-rhel9@sha256:f63db187b4171856a0ca46cf626a62fdd28deb3efc8dbf3522a188d774ada24b_s390x as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-openshift-controller-manager-rhel9@sha256:f63db187b4171856a0ca46cf626a62fdd28deb3efc8dbf3522a188d774ada24b_s390x
Red Hatopenshift4/ose-tests-rhel9@sha256:f080cd3d5281604dc175e10ccf8fe8aa2c82582d42cc39fd390ac28814472699_s390x as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-csi-snapshot-validation-webhook-rhel9@sha256:d289db1238d04bf05093238cdb5779f62495783d779d53242f507cc32bad0d57_ppc64le as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-csi-snapshot-validation-webhook-rhel9@sha256:d289db1238d04bf05093238cdb5779f62495783d779d53242f507cc32bad0d57_ppc64le
Red Hatopenshift4/ose-cluster-config-rhel9-operator@sha256:47f32912ab6738db806cac98e97600f74741c5a61f5b7e86de87ddb91f785e6e_amd64 as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-configmap-reloader-rhel9@sha256:e8c7ac1e75c8f317fee3d5361be32b7ea0ca2fd9a63dce85bb9e9290d0a02728_ppc64le as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-configmap-reloader-rhel9@sha256:e8c7ac1e75c8f317fee3d5361be32b7ea0ca2fd9a63dce85bb9e9290d0a02728_ppc64le
Red Hatopenshift4/ose-cluster-storage-rhel9-operator@sha256:f9364c61b912d2c80d004a475d89caed12cfd61cf7f73a73c2babc51f095f746_amd64 as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-olm-catalogd-rhel9@sha256:1a14b774fb51fa2a1f1a836b9fb5bd1f9beb2300fe3bee920bfb5f9f18a0dff7_amd64 as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-olm-catalogd-rhel9@sha256:1a14b774fb51fa2a1f1a836b9fb5bd1f9beb2300fe3bee920bfb5f9f18a0dff7_amd64
Red Hatopenshift4/ose-monitoring-plugin-rhel9@sha256:1dbdb413cf0fc5aec9774182a245074d22b25724c737610e158b32f503f468ec_s390x as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-monitoring-plugin-rhel9@sha256:1dbdb413cf0fc5aec9774182a245074d22b25724c737610e158b32f503f468ec_s390x
Red Hatopenshift4/ose-kubevirt-cloud-controller-manager-rhel9@sha256:ec6edbda7b15ca1e5eef2090b881517aa19e711ded3c08b62b98c4c752ea3620_s390x as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-kubevirt-cloud-controller-manager-rhel9@sha256:ec6edbda7b15ca1e5eef2090b881517aa19e711ded3c08b62b98c4c752ea3620_s390x
Red Hatopenshift4/ose-prometheus-rhel9-operator@sha256:260f22a1ecf977c42d1c531b0b644ea8f2c65ac48f08d2b3d163c7f25418a380_ppc64le as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-prometheus-rhel9-operator@sha256:260f22a1ecf977c42d1c531b0b644ea8f2c65ac48f08d2b3d163c7f25418a380_ppc64le
Red Hatopenshift4/ose-cluster-samples-rhel9-operator@sha256:dda9224d009dc8d3722a632e555757528ab146d79affceed18f671d2b96358ca_s390x as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-cluster-samples-rhel9-operator@sha256:dda9224d009dc8d3722a632e555757528ab146d79affceed18f671d2b96358ca_s390x
Red Hatopenshift4/ose-oauth-apiserver-rhel9@sha256:643db222a422e47cf694bcae745e06c78e69abe9652d4168d88ffef44bc86db7_arm64 as a component of Red Hat OpenShift Container Platform 4.16*
Red Hatopenshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:4e49abd8a9ef3869cdf773383d82de5d9b1ab02c1c355493382475b6e6a1f424_ppc64le as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:4e49abd8a9ef3869cdf773383d82de5d9b1ab02c1c355493382475b6e6a1f424_ppc64le
Red Hatopenshift4/ose-cluster-api-rhel9@sha256:357d1d57dc0c73c7a19ff52f75cd5985a87fff09297942fefd060d5ac51359ab_amd64 as a component of Red Hat OpenShift Container Platform 4.16openshift4/ose-cluster-api-rhel9@sha256:357d1d57dc0c73c7a19ff52f75cd5985a87fff09297942fefd060d5ac51359ab_amd64
Red Hatopenshift4/ose-installer-altinfra-rhel9@sha256:73a02bb501c78691a872ea71af37c1cb0166c908b8b699fdde3436ab5f221c24_amd64 as a component of Red Hat OpenShift Container Platform 4.16*

…and 1304 more

Timeline

  • Jul 9, 2024 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Aug 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›