VDB
RHSA-2024%3A6738
RHSA-2024%3A6738
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | multicluster-engine/addon-manager-rhel9@sha256:4b0f3d32fe6b84b8cc0230a19ccd28a69e2c30fb514106ca905c2f73f7805a29_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/cluster-api-provider-aws-rhel9@sha256:2cc307b1ae009760bfac991891d8703af78a2133bfd57c87ef4da55dba172847_amd64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/backplane-rhel9-operator@sha256:65bf78a3aeb2c7b9e0d326bad49c0a665c8d399272c2499cab660ab21b55c8eb_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | multicluster-engine/backplane-rhel9-operator@sha256:65bf78a3aeb2c7b9e0d326bad49c0a665c8d399272c2499cab660ab21b55c8eb_ppc64le, multicluster-engine/backplane-rhel9-operator@sha256:65bf78a3aeb2c7b9e0d326bad49c0a665c8d399272c2499cab660ab21b55c8eb_ppc64le, multicluster-engine/backplane-rhel9-operator@sha256:65bf78a3aeb2c7b9e0d326bad49c0a665c8d399272c2499cab660ab21b55c8eb_ppc64le |
| Red Hat | multicluster-engine/clusterclaims-controller-rhel9@sha256:471acafa3e2821f6f8336af2d875cc2d4173b73ab706d4e545cb8ba8df87e7ca_s390x as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/cluster-image-set-controller-rhel9@sha256:708c4c117db7251f636f00674e1601bb0d3632f466a49e6d47ae8d9e0fd76e15_amd64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/cluster-proxy-rhel9@sha256:122e6687332cc9396b724a8e14c741b8cce1ce5c27a263b5d66c5ccd6d79a263_arm64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/assisted-installer-rhel8@sha256:1885a89add15c4c358321a3ee13fa597e812867d0156db637b4604e8ca455d47_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 8 | * |
| Red Hat | multicluster-engine/work-rhel9@sha256:01b331b25b13064f02a490d1a5c605f996a127631e83e1710c7cfa21fcb8cccb_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | *, multicluster-engine/work-rhel9@sha256:01b331b25b13064f02a490d1a5c605f996a127631e83e1710c7cfa21fcb8cccb_ppc64le, multicluster-engine/work-rhel9@sha256:01b331b25b13064f02a490d1a5c605f996a127631e83e1710c7cfa21fcb8cccb_ppc64le |
| Red Hat | multicluster-engine/mce-operator-bundle@sha256:6b4d76d8426a36f4dee9c182a04d42f70d41d9c829528c939110c630232b73ba_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/hypershift-rhel9-operator@sha256:dc770a12d193326a12d9a617cf7db5af6e2d5ae4d74fa7feddc8829815de3b8b_s390x as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/console-mce-rhel9@sha256:e8a48f1a9cd9a622d866422b7c0dea2fe522c64e702c50addd33e213b8bd712e_s390x as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/multicluster-engine-hypershift-addon-rhel9-operator@sha256:d7ce509d9267b7fe32756a63e891122222465037fc25f8e02649a8543d4465da_arm64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | multicluster-engine/multicluster-engine-hypershift-addon-rhel9-operator@sha256:d7ce509d9267b7fe32756a63e891122222465037fc25f8e02649a8543d4465da_arm64, multicluster-engine/multicluster-engine-hypershift-addon-rhel9-operator@sha256:d7ce509d9267b7fe32756a63e891122222465037fc25f8e02649a8543d4465da_arm64, multicluster-engine/multicluster-engine-hypershift-addon-rhel9-operator@sha256:d7ce509d9267b7fe32756a63e891122222465037fc25f8e02649a8543d4465da_arm64 |
| Red Hat | multicluster-engine/managedcluster-import-controller-rhel9@sha256:abea5abbe13923982ff88e99ccdae765b1e1fddb9bdc7fdfe1bfbf8a28ec102c_amd64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:80c058818491264d99301e777579f571d9e517bec45cd65f323f388934c4807f_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:80c058818491264d99301e777579f571d9e517bec45cd65f323f388934c4807f_ppc64le, multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:80c058818491264d99301e777579f571d9e517bec45cd65f323f388934c4807f_ppc64le, * |
| Red Hat | multicluster-engine/cluster-api-provider-azure-rhel9@sha256:c3c0e45e0769e3a85841f91dbdb8209278f818218f5ad10bb3608c787cc96329_arm64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/placement-rhel9@sha256:f89d8410f848df3f258fe2bbb9f4c851010611ee6255e8db9e1abe4fa5db9d0a_amd64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/work-rhel9@sha256:01b331b25b13064f02a490d1a5c605f996a127631e83e1710c7cfa21fcb8cccb_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/cluster-api-provider-azure-rhel9@sha256:3a97fe144c1ca86629d8ecba416b40b03bb5f63b42347d1bf6744925da7fd498_amd64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | *, *, * |
| Red Hat | multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:866a59dcd6cd7f380420e3a2c190c212b14f4fbe46820a02fc193ca7925063aa_amd64 as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
| Red Hat | multicluster-engine/hypershift-addon-rhel9-operator@sha256:58f16924b2259b3e4e38775d1f848461bdd8408dc8754248c4e5f94524ee5263_ppc64le as a component of multicluster engine for Kubernetes 2.5 for RHEL 9 | * |
…and 316 more
Timeline
- Sep 17, 2024 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2302458 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_6738.json advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://access.redhat.com/security/cve/CVE-2024-42459 advisory
- https://access.redhat.com/security/cve/CVE-2024-48949 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-48949 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-42460 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-42460 advisory
- https://access.redhat.com/security/cve/CVE-2024-42461 advisory
- https://github.com/advisories/GHSA-49q7-c7j4-3p7m advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2302459 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2302460 issue
- https://github.com/indutny/elliptic/pull/317 advisory
- https://access.redhat.com/security/cve/CVE-2024-42460 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-42461 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-48949 advisory
- https://access.redhat.com/errata/RHSA-2024:6738 advisory
…and 7 more