VDB
RHSA-2024:5199
RHSA-2024:5199
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-tech-preview/metallb-rhel8@sha256:7223d061d22f302dc85031b68884fefdc5b958570878f57d6c27a6a89fd9d15b_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift-tech-preview/metallb-rhel8@sha256:7223d061d22f302dc85031b68884fefdc5b958570878f57d6c27a6a89fd9d15b_s390x |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:e4875d4cd1ba26f409209793bcbe193bd3acb3e6dcb25a87e56b1a7186bc2bc6_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:63d4b27c169da993597f5eaec2950c54c7021708b996cb220a1d91062c1ef354_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:63d4b27c169da993597f5eaec2950c54c7021708b996cb220a1d91062c1ef354_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-sriov-infiniband-cni@sha256:e09a35c48bd4c35f402fa9aa2b5b7dd95c12a633dfdc780e1207fddc0ea67041_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8@sha256:4b301eabc55306f6f8dc3a13facabd8d174ef28b6bf7b7343e3da4977566524f_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:ac427fc5e250621eb40115e353509a680280ef3011b60d7c6c68a35c5678aa0d_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:ac427fc5e250621eb40115e353509a680280ef3011b60d7c6c68a35c5678aa0d_amd64 |
| Red Hat | openshift4/metallb-rhel8@sha256:ad27c0b9b0204a8b9cb83b793833856f579b30d07ecf25b880fb47f05d05c485_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:82b2cdc2dafbef35f46c62cec2efdaa3ccb567f6655ef545bcc55d051cbc75d3_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:82b2cdc2dafbef35f46c62cec2efdaa3ccb567f6655ef545bcc55d051cbc75d3_amd64 |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:44ff91e83a520f796e62e59e37d06a369e2592c859e7d3470a1f56c85b008c94_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:44ff91e83a520f796e62e59e37d06a369e2592c859e7d3470a1f56c85b008c94_amd64 |
| Red Hat | openshift4/ose-cloud-event-proxy@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cloud-event-proxy@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 |
| Red Hat | openshift4/frr-rhel8@sha256:d2691d12b3c543aad5a105053e42452d9529e2a7fb92f49522b92af1ced0c09a_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:51d2f6d3288efadce73de30f4171306d60a4a629e3aa2b414a566f191e93bea2_s390x as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:1394690174b33ffc4f08e48038450bce3a3a933dfe209ea37d7e1e9f7153b441_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:435ec4fb18e43d0209e191660c91aa6eb8dc932fe5a0aea16ebd04c30d8fd9bb_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-nfd-operator@sha256:435ec4fb18e43d0209e191660c91aa6eb8dc932fe5a0aea16ebd04c30d8fd9bb_s390x |
| Red Hat | openshift4/ose-cluster-kube-descheduler-operator@sha256:63d4b27c169da993597f5eaec2950c54c7021708b996cb220a1d91062c1ef354_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cluster-kube-descheduler-operator@sha256:63d4b27c169da993597f5eaec2950c54c7021708b996cb220a1d91062c1ef354_s390x |
| Red Hat | openshift4/ose-egress-dns-proxy@sha256:129b1327aa5adc059c79a2bbd904bf1dbd23dc4362286e2220b404fbb9748f53_s390x as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-egress-dns-proxy@sha256:129b1327aa5adc059c79a2bbd904bf1dbd23dc4362286e2220b404fbb9748f53_s390x |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:10883a0c90db6a5b67b74fb5fc17adfb5b9a1d8c0220f6ee20aa5529a44ef7c7_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | * |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel8@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-cloud-event-proxy-rhel8@sha256:fbd89aab3dc3462c1b100677fc5f383eb2970fb45716223d1c48b1409f0a1d45_amd64 |
| Red Hat | openshift4/ose-local-storage-operator@sha256:31682a3390e45bd8b47cecc3390ad1f89f47889d50077289235c8d8c15dccc62_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-local-storage-operator@sha256:31682a3390e45bd8b47cecc3390ad1f89f47889d50077289235c8d8c15dccc62_amd64 |
…and 122 more
Timeline
- Aug 19, 2024 CVE Published
- Apr 25, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://access.redhat.com/errata/RHSA-2024:5199 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5199.json advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory