VDB
RHSA-2024:7744
RHSA-2024:7744
PUBLISHED
CVSS 6 MEDIUM
A vulnerability was found in go-retryablehttp. The package may suffer from a lack of input sanitization by not cleaning up URL data when writing to the logs. This issue could expose sensitive authentication information.
Risk Scores
CVSS 3.1
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:7e582ef2d0c4bc71fb076f0053b8ea427589ac04401e7ce7def6e675239754e8_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odf-csi-addons-sidecar-rhel9@sha256:7e582ef2d0c4bc71fb076f0053b8ea427589ac04401e7ce7def6e675239754e8_s390x |
| Red Hat | odf4/odf-rhel9-operator@sha256:320ba21a8a9eb525a9583a58089d435e30e650376cb6d225ab6111f30ceeab92_ppc64le as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odr-rhel9-operator@sha256:d0c1c6430224329f516bdd84da6165425b3a56ca559051f8b0a4aa2ffad5bc72_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/odr-rhel9-operator@sha256:d0c1c6430224329f516bdd84da6165425b3a56ca559051f8b0a4aa2ffad5bc72_amd64 |
| Red Hat | odf4/mcg-rhel9-operator@sha256:fccd722c86aa2f30449264df7629a617713389e9d90b13d4ab935b0adfeb6853_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odr-cluster-operator-bundle@sha256:3685cf22ae0d67dbcf7733cfaf38470dae937e8fc8742622ae2db0b423bb490e_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odf-csi-addons-rhel9-operator@sha256:716c9f2ed4e94b221a9ae193cdb885bb33c2570a5eb7eddc65136f49260bbd8e_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:6d0c856b4a25f0af688d6c94f370d56a07e91244dd1f4f8953bade12cdb3102c_s390x as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odr-cluster-operator-bundle@sha256:a5c5d488a7c221b31168c01e59b60e6525dfb3279acc43a4bed6ef6045eefc05_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odr-cluster-operator-bundle@sha256:a5c5d488a7c221b31168c01e59b60e6525dfb3279acc43a4bed6ef6045eefc05_s390x |
| Red Hat | odf4/mcg-operator-bundle@sha256:8236c3713d044755faa5fd45013db3d3c5bb57bf9578b8329dc42857f3c03486_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/ocs-operator-bundle@sha256:edb98687c8bd8848ce21f30386fb125c990fc90f7cca008ff65c08e95ecee14d_ppc64le as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odr-rhel9-operator@sha256:1a210010daa0a59fd37737369a1594969a3f96b7a7bcf0b1acfe8f5361fe4b09_arm64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odf-console-rhel9@sha256:c34066b6da780d6cd41fae5b5ac8f3df74687a602e755171ef32e668030bd5eb_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/odf-console-rhel9@sha256:c34066b6da780d6cd41fae5b5ac8f3df74687a602e755171ef32e668030bd5eb_amd64 |
| Red Hat | odf4/odf-csi-addons-rhel9-operator@sha256:645df6b561bd66f98f0e713e86b1011c33a960ecccde05072d530719885068c3_ppc64le as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/odf-operator-bundle@sha256:b09dafec40fac60225908f3e1101de567f1378e703d44ef9c405d7abad41be34_s390x as a component of RHODF 4.13 for RHEL 9 | odf4/odf-operator-bundle@sha256:b09dafec40fac60225908f3e1101de567f1378e703d44ef9c405d7abad41be34_s390x |
| Red Hat | odf4/ocs-rhel9-operator@sha256:84de226a3d678009245d4ae6b5e09674ebc19ce334f130f40707c88ce1f97025_s390x as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/ocs-client-operator-bundle@sha256:a37b2179b5938b096789b9e8290672f7b61ede937b5a0342d37a000a538152ec_s390x as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/cephcsi-rhel9@sha256:bb60d9f0df57b5de44ca2d6e92d28dfba9717daecea1da58b136183c3e5240cc_amd64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:fccd722c86aa2f30449264df7629a617713389e9d90b13d4ab935b0adfeb6853_amd64 as a component of RHODF 4.13 for RHEL 9 | odf4/mcg-rhel9-operator@sha256:fccd722c86aa2f30449264df7629a617713389e9d90b13d4ab935b0adfeb6853_amd64 |
| Red Hat | odf4/mcg-cli-rhel9@sha256:6cce948341b71e914998e5e74b6d20b4197788707ea70fe12da6524ca944592d_arm64 as a component of RHODF 4.13 for RHEL 9 | * |
| Red Hat | odf4/ocs-client-rhel9-operator@sha256:995d5b383529e936191f9b068ef4ed791dfdc6c8124be02b6e638744d408dcec_s390x as a component of RHODF 4.13 for RHEL 9 | * |
…and 146 more
Timeline
- Oct 7, 2024 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Aug 4, 2026 CVE Updated
- Aug 4, 2026 Distribution Patch
References
- https://access.redhat.com/errata/RHSA-2024:7744 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2294000 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2314153 issue
- https://nvd.nist.gov/vuln/detail/CVE-2024-6104 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/security/cve/CVE-2024-6104 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7744.json advisory
- https://www.cve.org/CVERecord?id=CVE-2024-6104 advisory