VDB
RHSA-2024%3A7237
RHSA-2024%3A7237
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:175ca15c6abd49f5e63931ab0045ba9efe552f700824f4b8984c912aad46e071_ppc64le as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:93241919e664dba00a76eb9eb9961ea4b4c8f9aa36d643575236f07be66551c4_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:93241919e664dba00a76eb9eb9961ea4b4c8f9aa36d643575236f07be66551c4_arm64 |
| Red Hat | openshift-logging/logging-curator5-rhel9@sha256:a87cb11c6991e887263d3cc0e9f428c2fe7b1dbc499c260ce3d91403d36c1948_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-curator5-rhel9@sha256:a87cb11c6991e887263d3cc0e9f428c2fe7b1dbc499c260ce3d91403d36c1948_s390x |
| Red Hat | openshift-logging/loki-operator-bundle@sha256:323077959144e1268cda4938e7c605d4d926e7306d0ebcb4f48486c0c0bee2e9_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/loki-operator-bundle@sha256:323077959144e1268cda4938e7c605d4d926e7306d0ebcb4f48486c0c0bee2e9_amd64 |
| Red Hat | openshift-logging/cluster-logging-operator-bundle@sha256:9fb2edd638ad211f2198c4525ff3b8bf0a0bd3063a2bf8970f64542cacb72297_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/cluster-logging-operator-bundle@sha256:9fb2edd638ad211f2198c4525ff3b8bf0a0bd3063a2bf8970f64542cacb72297_amd64 |
| Red Hat | openshift-logging/elasticsearch-rhel9-operator@sha256:6b71841725fd505df5ad4ea1087df170991ec4cec6fab95ab6369e06315c6b79_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-rhel9-operator@sha256:6b71841725fd505df5ad4ea1087df170991ec4cec6fab95ab6369e06315c6b79_amd64 |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:24180b4ed3274ce8d33ea2a7406f3d642b52be135fa4b1f9887c84121b3b17f9_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/fluentd-rhel9@sha256:24180b4ed3274ce8d33ea2a7406f3d642b52be135fa4b1f9887c84121b3b17f9_amd64 |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:377bbf02e095c50fac2304fa6860781f7f602315382b4256738f16aeab2cec33_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:377bbf02e095c50fac2304fa6860781f7f602315382b4256738f16aeab2cec33_amd64 |
| Red Hat | openshift-logging/elasticsearch6-rhel9@sha256:83dccefd20b2e4d8c2a76644d0346b46b3af86fde07bccbb0b8057fe65fb92be_ppc64le as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/logging-view-plugin-rhel9@sha256:3df70f353b018be62764b51edc9d0115341aa80f99087bd81d9d667a39100e71_arm64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-view-plugin-rhel9@sha256:3df70f353b018be62764b51edc9d0115341aa80f99087bd81d9d667a39100e71_arm64 |
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:bba377dd7ee50bbc9c258239ecee1614123b69bc2e036debfb14abf625314c16_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/cluster-logging-rhel9-operator@sha256:bba377dd7ee50bbc9c258239ecee1614123b69bc2e036debfb14abf625314c16_s390x |
| Red Hat | openshift-logging/elasticsearch-operator-bundle@sha256:f10faba1a512f74de91428b4115a44a81caceb8a6421208af40325e35f42d80f_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch-operator-bundle@sha256:f10faba1a512f74de91428b4115a44a81caceb8a6421208af40325e35f42d80f_amd64 |
| Red Hat | openshift-logging/logging-curator5-rhel9@sha256:ae61ad03a2d5c7031ad3e7bb6ccbcb6fe21b115ec7015560bb48e4f84203ea71_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/logging-curator5-rhel9@sha256:ae61ad03a2d5c7031ad3e7bb6ccbcb6fe21b115ec7015560bb48e4f84203ea71_ppc64le |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:192e6f52c57d25e73e1574c7ec6d289d5ab3d689cc7018cb28dfa1532d12a414_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:192e6f52c57d25e73e1574c7ec6d289d5ab3d689cc7018cb28dfa1532d12a414_ppc64le |
| Red Hat | openshift-logging/elasticsearch6-rhel9@sha256:778a3f776e7eacb7a13ff5ab52f7261ab98e0140a8b4576353de4dcc3aa93ee6_s390x as a component of RHOL 5.8 for RHEL 9 | openshift-logging/elasticsearch6-rhel9@sha256:778a3f776e7eacb7a13ff5ab52f7261ab98e0140a8b4576353de4dcc3aa93ee6_s390x |
| Red Hat | openshift-logging/logging-view-plugin-rhel9@sha256:63b9805cb4789b8f4eddc18a1858db89981d5ab47aaa6b2abaae76268bf4fff2_amd64 as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:0588e4bc5c93cd7ffaa7e62e777ddb312a370f3ae0abe086c693307e618df491_amd64 as a component of RHOL 5.8 for RHEL 9 | * |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:cfaf9d86a604739e8abdad148a4da0b6fcbf37eb29685a8dfd9705b4b517694b_amd64 as a component of RHOL 5.8 for RHEL 9 | openshift-logging/loki-rhel9-operator@sha256:cfaf9d86a604739e8abdad148a4da0b6fcbf37eb29685a8dfd9705b4b517694b_amd64 |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:6dda829d6d0cebe59f9d931a1bc8a3a9a08d53a460846608558538a831a1841b_ppc64le as a component of RHOL 5.8 for RHEL 9 | openshift-logging/eventrouter-rhel9@sha256:6dda829d6d0cebe59f9d931a1bc8a3a9a08d53a460846608558538a831a1841b_ppc64le |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:196d4a30c1a2c862cede41b31157516e9a503daf3e830975ec4678e5b163c119_s390x as a component of RHOL 5.8 for RHEL 9 | * |
…and 39 more
Timeline
- Sep 26, 2024 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:7237 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://issues.redhat.com/browse/LOG-5210 advisory
- https://issues.redhat.com/browse/LOG-5966 advisory
- https://issues.redhat.com/browse/LOG-6103 advisory
- https://issues.redhat.com/browse/LOG-6127 advisory
- https://issues.redhat.com/browse/LOG-6134 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7237.json advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory