Threats Tagged 'cve-2024-43788'
View all threats tagged with 'cve-2024-43788'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-43788'
Click on any threat for detailed analysis and mitigation recommendations
The 1.15.4 release of Red Hat OpenShift Pipelines Operator. Join the discussion | GCVE Database | 03/04/2026, 07:52:57 UTC Added: 05/26/2026, 20:58:30 UTC |
GCVE Database | 02/05/2026, 18:06:29 UTC Added: 05/26/2026, 20:58:31 UTC | |
GCVE Database | 02/05/2026, 17:49:21 UTC Added: 05/26/2026, 20:58:23 UTC | |
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale. Data Grid 8.5.2 replaces Data Grid 8.5.1 and includes bug fixes and enhancements. Find out more about Data Grid 8.5.2 in the Release Notes[3]. Security Fix(es): * CVE-2024-47072 com.thoughtworks.xstream/xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream [jdg-8] (CVE-2024-47072) * CVE-2024-43788 webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule [jdg-8] (CVE-2024-43788) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 11/25/2024, 16:56:04 UTC Added: 06/02/2026, 21:44:01 UTC |
0 Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3 compatible API. Bug fixes: * Previously, on the disaster recover (DR) monitoring dashboard, the detail about `Last snapshot synced` was missing for appset based applications. With this fix, the dashboard shows the `lastGroupSyncTime` under the `Volume snapshot` for the selected appset based applications. (BZ#2295324) * Previously, when OpenShift Data Foundation was installed in a namespace other than `openshift-storage`, such as ROSA, the user interface (UI) labelled the nodes during the StorageSystem deployment and added a dynamic label "cluster.ocs.openshift.io/<CLUSTER_NAMESPACE>: ‘'", where "CLUSTER_NAMESPACE" is the namespace in which the StorageSystem is getting created). However the ODF/OCS operators expected the label to be always a static label, "cluster.ocs.openshift.io/openshift-storage: ‘’. With this fix, the user interface adds a static label "cluster.ocs.openshift.io/openshift-storage: ‘’ to the nodes and as a result the installation proceeds as expected. (BZ#2303083) Enhancement: * In the storage clients table of the Storage clients page of the OpenShift web console, storage cluster name is displayed along with the cluster ID to provide better clarity. (BZ#2304905) All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes. Join the discussion | GCVE Database | 10/15/2024, 08:52:38 UTC Added: 06/02/2026, 21:44:01 UTC |
0 This release includes security, bug fixes, and enhancements. Security Fix(es): * axios: axios: Server-Side Request Forgery (CVE-2024-39338) * express: Improper Input Handling in Express Redirects (CVE-2024-43796) * io.vertx/vertx-grpc-client: Vertx gRPC server does not limit the maximum message size (CVE-2024-8391) * io.vertx/vertx-grpc-server: Vertx gRPC server does not limit the maximum message size (CVE-2024-8391) * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) * webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section. Join the discussion | GCVE Database | 10/14/2024, 00:59:58 UTC Added: 06/02/2026, 21:43:30 UTC |
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) * webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) * envoy: Envoy incorrectly accepts HTTP 200 response for entering upgrade mode (CVE-2024-23326) * body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) * envoy: Brotli decompressor infinite loop (CVE-2024-32976) * envoy: abnormal termination when using auto_sni with authority header longer than 255 characters (CVE-2024-32475) * envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood (CVE-2024-30255) * envoy: Potential to manipulate `x-envoy` headers from external sources (CVE-2024-45806) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 10/07/2024, 09:24:53 UTC Added: 06/02/2026, 21:44:02 UTC |
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) * express: Improper Input Handling in Express Redirects (CVE-2024-43796) * path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) * webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) * body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) * envoy: Malicious log injection via access logs (CVE-2024-45808) * envoy: Potential to manipulate `x-envoy` headers from external sources (CVE-2024-45806) * envoy: Envoy crashes for `LocalReply` in HTTP async client (CVE-2024-45810) * curl: libcurl: ASN.1 date parser overread (CVE-2024-7264) * envoy: Potential to manipulate `x-envoy` headers from external sources (CVE-2024-45806) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 10/07/2024, 09:24:48 UTC Added: 06/02/2026, 21:44:01 UTC |
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * envoy: abnormal termination when using auto_sni with authority header longer than 255 characters (CVE-2024-32475) * envoy: Brotli decompressor infinite loop (CVE-2024-32976) * webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 10/07/2024, 09:22:37 UTC Added: 06/02/2026, 21:44:01 UTC |
An update is now available for the Red Hat build of Cryostat 3 on RHEL 8. Security Fix(es): * webpack: DOM Clobbering vulnerability in AutoPublicPathRuntimeModule (CVE-2024-43788) * dompurify: XSS vulnerability via prototype pollution (CVE-2024-45801) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 10/07/2024, 01:12:29 UTC Added: 06/02/2026, 21:44:01 UTC |
Showing 1 to 10 of 10 results