VDB
RHSA-2024:7324
RHSA-2024:7324
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-logging/logging-loki-rhel9@sha256:f6664dc6c451fae94f44aa48b7d7d33f57f5fde96dbddb9717f00865a26c167a_arm64 as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:c6bad5602c46f96702e1a8229d4cf2d0a52448b52921baf956be73d13b17238a_arm64 as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:048295f3106b5c3681c5f3bd43fc189fb27974403983e097c118c0789ebe8f22_arm64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:048295f3106b5c3681c5f3bd43fc189fb27974403983e097c118c0789ebe8f22_arm64 |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:8fc51ae71af5522c84b6653fc9930b6d64b900396c6d253d340ac74ffd5ad300_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:8fc51ae71af5522c84b6653fc9930b6d64b900396c6d253d340ac74ffd5ad300_s390x |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:8a3d87c76ccca2710d4009c483ff3849c0db0097134bf522eedfac20236b72a3_arm64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:8a3d87c76ccca2710d4009c483ff3849c0db0097134bf522eedfac20236b72a3_arm64 |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:b4e6a62a9711825f16d61bce5ce8926773671aa0fa826122a0a9cc7ce0a35f04_ppc64le as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/loki-rhel9-operator@sha256:ce77679763582b1d79a0b1873ccad041c390f66d2b2731029424fd71a929c68a_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/loki-rhel9-operator@sha256:ce77679763582b1d79a0b1873ccad041c390f66d2b2731029424fd71a929c68a_s390x |
| Red Hat | openshift-logging/vector-rhel9@sha256:fa22505c9f61ec65d258125530bffe12e925be8e7f4479266c6e717eaed89aa5_s390x as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:55bddb959a24589db81c899b763d93e52d39c03e949341ab59139af4646657d7_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/eventrouter-rhel9@sha256:55bddb959a24589db81c899b763d93e52d39c03e949341ab59139af4646657d7_ppc64le |
| Red Hat | openshift-logging/lokistack-gateway-rhel9@sha256:23758e547a97de164a49e4b248a6548d9a738fafd3410702dce8c3eaa6c726ea_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/lokistack-gateway-rhel9@sha256:23758e547a97de164a49e4b248a6548d9a738fafd3410702dce8c3eaa6c726ea_ppc64le |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:473a6e8f3f9b879038eeffbd9ea3f1ce51fd30e2614598f5ed96a9699e1e0840_s390x as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/logging-loki-rhel9@sha256:4f887ba3569acde13bf34fa86cd8e2899281f9d4efc83f6ddaf18cc39f9b8f24_s390x as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/fluentd-rhel9@sha256:e39aeb29fead7c4899b76b9fd90a03b49875de0660dc0f701885617c4ebd2ee5_ppc64le as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:2d2139f6b181b70ac42953f1eb1c473a370b6835c13a1042eaa95312873f3f4f_ppc64le as a component of RHOL 5.9 for RHEL 9 | openshift-logging/opa-openshift-rhel9@sha256:2d2139f6b181b70ac42953f1eb1c473a370b6835c13a1042eaa95312873f3f4f_ppc64le |
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:81429833f5eace1ed0551c24e36f4b62e6f8e636b0aaa9d51ca631bd38e39d55_amd64 as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/eventrouter-rhel9@sha256:55bddb959a24589db81c899b763d93e52d39c03e949341ab59139af4646657d7_ppc64le as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging | |
| Red Hat | openshift-logging/opa-openshift-rhel9@sha256:8fc51ae71af5522c84b6653fc9930b6d64b900396c6d253d340ac74ffd5ad300_s390x as a component of RHOL 5.9 for RHEL 9 | * |
| Red Hat | openshift-logging/log-file-metric-exporter-rhel9@sha256:0e20cce12cf234424ba883d582e4b5409d5abad895ea1411ed94400a919efa26_s390x as a component of RHOL 5.9 for RHEL 9 | openshift-logging/log-file-metric-exporter-rhel9@sha256:0e20cce12cf234424ba883d582e4b5409d5abad895ea1411ed94400a919efa26_s390x |
| Red Hat | openshift-logging/cluster-logging-rhel9-operator@sha256:81429833f5eace1ed0551c24e36f4b62e6f8e636b0aaa9d51ca631bd38e39d55_amd64 as a component of RHOL 5.9 for RHEL 9 | openshift-logging/cluster-logging-rhel9-operator@sha256:81429833f5eace1ed0551c24e36f4b62e6f8e636b0aaa9d51ca631bd38e39d55_amd64 |
…and 66 more
Timeline
- Oct 2, 2024 CVE Published
- Apr 25, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Distribution Patch
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
- Aug 4, 2026 Security Advisory
References
- https://issues.redhat.com/browse/LOG-5950 advisory
- https://issues.redhat.com/browse/LOG-6125 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45296 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2312631 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45801 advisory
- https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc advisory
- https://access.redhat.com/errata/RHSA-2024:7324 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://issues.redhat.com/browse/LOG-6041 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7324.json advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://access.redhat.com/security/cve/CVE-2024-45296 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2310908 issue
- https://www.cve.org/CVERecord?id=CVE-2024-45296 advisory
- https://github.com/pillarjs/path-to-regexp/commit/29b96b4a1de52824e1ca0f49a701183cc4ed476f advisory
- https://github.com/pillarjs/path-to-regexp/commit/60f2121e9b66b7b622cc01080df0aabda9eedee6 advisory
- https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-9wv6-86v2-598j advisory
…and 4 more