VDB

RHSA-2024:4321

RHSA-2024:4321 PUBLISHED CVSS 6 MEDIUM

A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.

Risk Scores

CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-cluster-olm-operator-rhel8@sha256:7243474fdbe5aa86f771e039cb3de02e9997aa9f27fdb66af5d688d0a2602209_arm64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-agent-installer-csr-approver-rhel8@sha256:f29c75594ebabf85c53707e9a7206a2d90106fdf221af162315f1258739c76d6_s390x as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-agent-installer-csr-approver-rhel8@sha256:f29c75594ebabf85c53707e9a7206a2d90106fdf221af162315f1258739c76d6_s390x
Red Hatopenshift4/ose-console@sha256:f354ec32667aeac5700c84f00abe9f5d5c5586b7ad4f9524224c23f784536ead_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-console@sha256:f354ec32667aeac5700c84f00abe9f5d5c5586b7ad4f9524224c23f784536ead_arm64
Red Hatopenshift4/ose-csi-node-driver-registrar@sha256:cf3cde68b9a6be5c385e1844cc91fb516039939e59374258e6c5b6f5e0aec097_amd64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-cli@sha256:06ecfaf3cb0d35651ce0a9678f0b06b321eaafd4cbb2fcbf3a9cb903a8c6c99a_s390x as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-installer-artifacts@sha256:80af774c6d2811ec0ded4920c6525d1e65d34be063a984c029017de57e6ff2da_s390x as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-installer-artifacts@sha256:80af774c6d2811ec0ded4920c6525d1e65d34be063a984c029017de57e6ff2da_s390x
Red Hatopenshift4/ose-console@sha256:f354ec32667aeac5700c84f00abe9f5d5c5586b7ad4f9524224c23f784536ead_arm64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-olm-catalogd-rhel8@sha256:50ff3f4f3ebc3f69937a1a9c8c2920ec46215804b1726792c1b6045258d40a14_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-pod-rhel9@sha256:46f14f0992822ab250f46a5dc978cd64b90f7cae6b7d896ab161e5a9b0a26b04_ppc64le as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-installer@sha256:ee42f67e799738b020a892892eaab528bc38c3ef128265be923bdcb2262cd9f4_amd64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-installer@sha256:ee42f67e799738b020a892892eaab528bc38c3ef128265be923bdcb2262cd9f4_amd64
Red Hatopenshift4/ose-multus-cni@sha256:96215a1f34edc30926a6f41b8122a77da5d864415167d2fe1f4b4c5f8b23e6d2_s390x as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:9b2561d4cf853286c0fb984dfef5553082ca0de2f8fd7d805e4b7281f2c9f805_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-openstack-cinder-csi-driver-rhel8-operator@sha256:9b2561d4cf853286c0fb984dfef5553082ca0de2f8fd7d805e4b7281f2c9f805_arm64
Red Hatopenshift4/ose-cluster-ingress-rhel9-operator@sha256:ce2855c5cf88f7c8b84fbf8537846a894fa7cc5fa02ab9d66eb15dbaaac9f959_ppc64le as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-cluster-ingress-rhel9-operator@sha256:ce2855c5cf88f7c8b84fbf8537846a894fa7cc5fa02ab9d66eb15dbaaac9f959_ppc64le
Red Hatopenshift4/kubevirt-csi-driver-rhel8@sha256:14c06d1167e368e1c839ad911b853cd19aaceb0900786c8faffe0ef86b969cc6_arm64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/kubevirt-csi-driver-rhel8@sha256:14c06d1167e368e1c839ad911b853cd19aaceb0900786c8faffe0ef86b969cc6_arm64
Red Hatopenshift4/ose-olm-catalogd-rhel8@sha256:107278fce3b40cb158d5c39b73c19a60221a2272acf12284db949dd93f43f047_arm64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/driver-toolkit-rhel9@sha256:e86afde0ec8161ccd16639225a2f5efca285509629760e63335667aefbd042ea_amd64 as a component of Red Hat OpenShift Container Platform 4.15openshift4/driver-toolkit-rhel9@sha256:e86afde0ec8161ccd16639225a2f5efca285509629760e63335667aefbd042ea_amd64
Red Hatopenshift4/ose-prom-label-proxy@sha256:02700acf39dbde247cd12873640a4fe691875fe5b602ac7fac693517807d5dfa_s390x as a component of Red Hat OpenShift Container Platform 4.15openshift4/ose-prom-label-proxy@sha256:02700acf39dbde247cd12873640a4fe691875fe5b602ac7fac693517807d5dfa_s390x
Red Hatopenshift4/ose-network-interface-bond-cni-rhel8@sha256:5dd4b46d7d2067a0a3d9a9da7396d26c96d730165a2a842ca31d62aac4df2448_arm64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/network-tools-rhel8@sha256:0968f83d3864bfce5af301a72a371360624674e815d24d409196bc65755a9869_arm64 as a component of Red Hat OpenShift Container Platform 4.15*
Red Hatopenshift4/ose-olm-catalogd-rhel8@sha256:5d398026f22d40b8df8209e83e5551406d2a2c973f2de43236cc7b71005b7cf1_s390x as a component of Red Hat OpenShift Container Platform 4.15*

…and 604 more

Timeline

  • Jul 10, 2024 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Aug 4, 2026 CVE Updated
  • Aug 4, 2026 Distribution Patch
  • Aug 4, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›