Red Hat Security Advisory: Cluster Observability Operator 0.4.1
Cluster Observability Operator Security Fix(es): * coo-prometheus-container: go-retryablehttp: url might write sensitive information to log file [coo-0] (CVE-2024-6104) * coo-thanos-container: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [coo-0] (CVE-2024-24786) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
AI Analysis
Technical Summary
This advisory covers multiple security fixes in Red Hat OpenShift Serverless Operator 1.33.1 and related components. Notably, CVE-2024-6104 addresses a vulnerability in the go-retryablehttp library where URLs might write sensitive information to log files. Additional fixes include CVE-2024-24789 for incorrect handling of certain ZIP files in golang's archive/zip package, CVE-2024-24790 for unexpected behavior in net/netip IPv4-mapped IPv6 address methods, and CVE-2024-24788 for an infinite loop caused by malformed DNS messages in golang's net package. The updates apply to Red Hat OpenShift Container Platform versions 4.12 through 4.17 and related operators such as Cluster Observability Operator and OpenShift Pipelines. The vendor advisory confirms these fixes and provides upgrade instructions.
Potential Impact
The vulnerabilities fixed could lead to sensitive information leakage through logging (CVE-2024-6104), incorrect processing of ZIP files potentially leading to unexpected behavior (CVE-2024-24789), unexpected behavior in IP address handling (CVE-2024-24790), and denial of service via infinite loops caused by malformed DNS messages (CVE-2024-24788). These issues affect the security and stability of Red Hat OpenShift Serverless and related components. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates for OpenShift Serverless Operator 1.33.1 and related components. Users should upgrade to the fixed versions as soon as they are available in their release channels. Detailed upgrade instructions are provided by Red Hat in their advisories and documentation. No additional mitigations are indicated beyond applying these official patches.
Red Hat Security Advisory: Cluster Observability Operator 0.4.1
Description
Cluster Observability Operator Security Fix(es): * coo-prometheus-container: go-retryablehttp: url might write sensitive information to log file [coo-0] (CVE-2024-6104) * coo-thanos-container: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [coo-0] (CVE-2024-24786) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers multiple security fixes in Red Hat OpenShift Serverless Operator 1.33.1 and related components. Notably, CVE-2024-6104 addresses a vulnerability in the go-retryablehttp library where URLs might write sensitive information to log files. Additional fixes include CVE-2024-24789 for incorrect handling of certain ZIP files in golang's archive/zip package, CVE-2024-24790 for unexpected behavior in net/netip IPv4-mapped IPv6 address methods, and CVE-2024-24788 for an infinite loop caused by malformed DNS messages in golang's net package. The updates apply to Red Hat OpenShift Container Platform versions 4.12 through 4.17 and related operators such as Cluster Observability Operator and OpenShift Pipelines. The vendor advisory confirms these fixes and provides upgrade instructions.
Potential Impact
The vulnerabilities fixed could lead to sensitive information leakage through logging (CVE-2024-6104), incorrect processing of ZIP files potentially leading to unexpected behavior (CVE-2024-24789), unexpected behavior in IP address handling (CVE-2024-24790), and denial of service via infinite loops caused by malformed DNS messages (CVE-2024-24788). These issues affect the security and stability of Red Hat OpenShift Serverless and related components. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released official security updates for OpenShift Serverless Operator 1.33.1 and related components. Users should upgrade to the fixed versions as soon as they are available in their release channels. Detailed upgrade instructions are provided by Red Hat in their advisories and documentation. No additional mitigations are indicated beyond applying these official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:11669
- Cve Count
- 4
- Additional Cves
- ["CVE-2024-45338","CVE-2025-22868","CVE-2025-30204"]
Threat ID: 6a16097ae29bf47b5064708f
Added to database: 05/26/2026, 20:58:34 UTC
Last enriched: 08/14/2026, 23:25:14 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.