VDB
RHSA-2024%3A7744
RHSA-2024%3A7744
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:7e582ef2d0c4bc71fb076f0053b8ea427589ac04401e7ce7def6e675239754e8_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odf-csi-addons-sidecar-rhel9@sha256:7e582ef2d0c4bc71fb076f0053b8ea427589ac04401e7ce7def6e675239754e8_s390x |
| Red Hat | odf4/odr-rhel9-operator@sha256:d0c1c6430224329f516bdd84da6165425b3a56ca559051f8b0a4aa2ffad5bc72_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/odr-rhel9-operator@sha256:d0c1c6430224329f516bdd84da6165425b3a56ca559051f8b0a4aa2ffad5bc72_amd64 |
| Red Hat | odf4/odr-cluster-operator-bundle@sha256:a5c5d488a7c221b31168c01e59b60e6525dfb3279acc43a4bed6ef6045eefc05_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odr-cluster-operator-bundle@sha256:a5c5d488a7c221b31168c01e59b60e6525dfb3279acc43a4bed6ef6045eefc05_s390x |
| Red Hat | odf4/ocs-operator-bundle@sha256:edb98687c8bd8848ce21f30386fb125c990fc90f7cca008ff65c08e95ecee14d_ppc64le as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odf-console-rhel9@sha256:c34066b6da780d6cd41fae5b5ac8f3df74687a602e755171ef32e668030bd5eb_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/odf-console-rhel9@sha256:c34066b6da780d6cd41fae5b5ac8f3df74687a602e755171ef32e668030bd5eb_amd64 |
| Red Hat | odf4/odf-operator-bundle@sha256:b09dafec40fac60225908f3e1101de567f1378e703d44ef9c405d7abad41be34_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odf-operator-bundle@sha256:b09dafec40fac60225908f3e1101de567f1378e703d44ef9c405d7abad41be34_s390x |
| Red Hat | odf4/ocs-client-operator-bundle@sha256:a37b2179b5938b096789b9e8290672f7b61ede937b5a0342d37a000a538152ec_s390x as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/cephcsi-rhel9@sha256:bb60d9f0df57b5de44ca2d6e92d28dfba9717daecea1da58b136183c3e5240cc_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:fccd722c86aa2f30449264df7629a617713389e9d90b13d4ab935b0adfeb6853_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/mcg-rhel9-operator@sha256:fccd722c86aa2f30449264df7629a617713389e9d90b13d4ab935b0adfeb6853_amd64 |
| Red Hat | odf4/ocs-operator-bundle@sha256:25556774921f64007174f47e6a430966f52f27fa8a8c2c52b33cc87a531925a8_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/mcg-core-rhel9@sha256:2765ea3cdaaac10832b3459a8f4f08267681f739c61cdcaa2fea6bbf2eb9f134_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/mcg-core-rhel9@sha256:2765ea3cdaaac10832b3459a8f4f08267681f739c61cdcaa2fea6bbf2eb9f134_amd64 |
| Red Hat | odf4/odf-csi-addons-rhel9-operator@sha256:c3113878f9f029c33a91c4fdcac863b00d9295286d3a5cd518b07413e7a5e4c9_s390x as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/mcg-core-rhel9@sha256:fde62aef68c578b88e0bbeb5f17686c3b460c24e49bd936527a1752afa7cc4c0_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/mcg-core-rhel9@sha256:fde62aef68c578b88e0bbeb5f17686c3b460c24e49bd936527a1752afa7cc4c0_s390x |
| Red Hat | odf4/mcg-cli-rhel9@sha256:9b0acc2a1b6cd7499441244edbb17a901addbd9e4eef54790530cfb79361e957_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/mcg-cli-rhel9@sha256:9b0acc2a1b6cd7499441244edbb17a901addbd9e4eef54790530cfb79361e957_s390x |
| Red Hat | odf4/odr-hub-operator-bundle@sha256:0cbfab6465176009ce9fe895209c79cd7b46815fd3629ed7a0ea23fdab0c34a2_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odr-hub-operator-bundle@sha256:0cbfab6465176009ce9fe895209c79cd7b46815fd3629ed7a0ea23fdab0c34a2_s390x |
| Red Hat | odf4/ocs-client-rhel9-operator@sha256:7b983a28dbe669d0c21b59ea87b970c4fdae4d930f49bca686d7caf9bf31bbee_arm64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:6d0c856b4a25f0af688d6c94f370d56a07e91244dd1f4f8953bade12cdb3102c_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odf-multicluster-console-rhel9@sha256:6d0c856b4a25f0af688d6c94f370d56a07e91244dd1f4f8953bade12cdb3102c_s390x |
| Red Hat | odf4/mcg-operator-bundle@sha256:c3f35146579b72cd1aef6c4ac75de35c698604c13cd66b225ffbd86b45cffffa_ppc64le as a component of RHODF 4.13 for RHEL 9 | odf4/mcg-operator-bundle@sha256:c3f35146579b72cd1aef6c4ac75de35c698604c13cd66b225ffbd86b45cffffa_ppc64le |
| Red Hat | odf4/rook-ceph-rhel9-operator@sha256:22528b22048b2ca01b690eac65fd6bcdf83b557ef97c6959fcb38b469e74ea72_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/rook-ceph-rhel9-operator@sha256:22528b22048b2ca01b690eac65fd6bcdf83b557ef97c6959fcb38b469e74ea72_s390x |
| Red Hat | odf4/odr-hub-operator-bundle@sha256:5e358a24db012b0a30924549ea591116268fcb8ad0387dc1a6797708fd9ca590_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/odr-hub-operator-bundle@sha256:5e358a24db012b0a30924549ea591116268fcb8ad0387dc1a6797708fd9ca590_amd64 |
…and 63 more
Timeline
- Oct 7, 2024 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:7744 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2314153 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7744.json advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory