Threats Tagged 'cve-2024-39338'
View all threats tagged with 'cve-2024-39338'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-39338'
Click on any threat for detailed analysis and mitigation recommendations
GCVE Database | 02/05/2026, 18:06:29 UTC Added: 05/26/2026, 20:58:31 UTC | |
GCVE Database | 02/05/2026, 17:49:21 UTC Added: 05/26/2026, 20:58:23 UTC | |
Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development. The 3.25 release is based on Eclipse Che 7.111 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2. Users still using the v1 standard should migrate as soon as possible. https://devfile.io/docs/2.2.0/migrating-to-devfile-v2 Dev Spaces supports OpenShift EUS releases v4.16 and higher. Users are expected to update to supported OpenShift releases in order to continue to get Dev Spaces updates. https://access.redhat.com/support/policy/updates/openshift#crw Join the discussion | GCVE Database | 12/15/2025, 21:46:21 UTC Added: 06/01/2026, 21:15:21 UTC |
Quay 3.11.7 Join the discussion | GCVE Database | 12/19/2024, 16:07:05 UTC Added: 06/02/2026, 21:43:31 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.4. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2024:8984 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.openshift.com/container-platform/4.17/release_notes/ocp-4-17-release-notes.html Security Fix(es): * axios: axios: Server-Side Request Forgery (CVE-2024-39338) * dompurify: nesting-based mutation XSS vulnerability (CVE-2024-47875) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Join the discussion | GCVE Database | 11/13/2024, 04:13:47 UTC Added: 06/02/2026, 21:43:30 UTC |
0 This release includes security, bug fixes, and enhancements. Security Fix(es): * axios: axios: Server-Side Request Forgery (CVE-2024-39338) * express: Improper Input Handling in Express Redirects (CVE-2024-43796) * io.vertx/vertx-grpc-client: Vertx gRPC server does not limit the maximum message size (CVE-2024-8391) * io.vertx/vertx-grpc-server: Vertx gRPC server does not limit the maximum message size (CVE-2024-8391) * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) * webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section. Join the discussion | GCVE Database | 10/14/2024, 00:59:58 UTC Added: 06/02/2026, 21:43:30 UTC |
0 Red Hat OpenShift Pipelines is a cloud-native continuous integration and delivery (CI/CD) solution for building pipelines using Tekton. Tekton is a flexible, Kubernetes-native, open-source CI/CD framework which enables automating deployments across multiple platforms such as Kubernetes, Serverless, and VMs by abstracting away the underlying details. Red Hat OpenShift Pipelines consists of: - Tekton Operator 0.73.x - Tekton Pipelines 0.62.x - Tekton Triggers 0.29.x - Tekton tkn CLI 0.38.x - Tekton Chains 0.22.x (GA) - Pipelines-as-Code 0.28.x (GA) - ClusterTasks based on Tekton Catalog - Tekton Hub 1.18.x (TP) - Tekton Result 0.11.x (TP) - Manual-Approval-Gate 0.3.x (TP) ## Features - Standard CI/CD pipelines definition - Easy to extend and integrate with existing tools - Portable across any Kubernetes platform - Designed for microservices and decentralized teams - Integrated with OpenShift Developer Console - Build images with Kubernetes tools such as S2I, Buildah, Buildpacks, Kaniko, etc. - Deploy applications to multiple platforms such as Kubernetes, Serverless, and VMs - Scale pipelines on-demand - Enhance supply chain security with Tekton Chains (Technology Preview) - Install and deploy Tekton Hub (Technology Preview) with custom catalog on enterprise cluster - Maintain pipelines definitions as parts of an application repository with Pipelines-as-Code (PAC) (General Availability) For more information, see the Release Notes on any one of the following platforms: - Customer Portal: https://access.redhat.com/documentation/en-us/red_hat_openshift_pipelines/1.14/html/about_openshift_pipelines/op-release-notes#op-release-notes-1-14_op-release-notes - OpenShift documentation: https://docs.openshift.com/pipelines/1.14/about/op-release-notes.html#op-release-notes-1-14_op-release-notes Join the discussion | GCVE Database | 10/09/2024, 14:44:53 UTC Added: 06/02/2026, 21:43:31 UTC |
Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins. Join the discussion | GCVE Database | 10/02/2024, 15:29:03 UTC Added: 06/01/2026, 21:15:21 UTC |
0 Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * axios: Server-Side Request Forgery (CVE-2024-39338) * elliptic: nodejs/elliptic: From NVD collector (CVE-2024-42459) * ECDSA signature malleability due to missing checks (CVE-2024-42460) * ECDSA implementation malleability due to BER-enconded signatures being allowed (CVE-2024-42461) * jose-go: improper handling of highly compressed data (CVE-2024-28180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/03/2024, 10:04:55 UTC Added: 05/28/2026, 20:54:05 UTC |
0 axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Join the discussion | CVE Database V5 | 08/09/2024, 00:00:00 UTC Added: 02/25/2026, 21:41:26 UTC |
Showing 1 to 10 of 10 results