Threats Tagged 'cve-2024-52798'
View all threats tagged with 'cve-2024-52798'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-52798'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: OpenShift Container Platform 4.17.15 bug fix and security updateCVE-2024-9676 0 Red Hat OpenShift Container Platform 4. 17. 15 includes security updates addressing two vulnerabilities: a symlink traversal vulnerability in the containers/storage library (CVE-2024-9676) that can cause denial of service, and a Regular Expression Denial of Service (ReDoS) vulnerability in the path-to-regexp library (CVE-2024-52798). These issues are rated as moderate severity by Red Hat. Users of OpenShift Container Platform 4. 17 are advised to upgrade to the updated packages and container images provided in this release to mitigate these vulnerabilities. Join the discussion | GCVE Database | 02/05/2025, 13:37:42 UTC Added: 06/02/2026, 21:43:37 UTC |
Red Hat Security Advisory: HawtIO 4.2.0 for Red Hat build of Apache Camel 4 Release and security update.CVE-2024-12397 0 Red Hat has released HawtIO 4. 2. 0 for the Red Hat build of Apache Camel 4 GA Release, addressing multiple security vulnerabilities. These include a Regular Expression Denial of Service (ReDoS) in path-to-regexp (CVE-2024-52798), HTTP Cookie Smuggling in Quarkus HTTP core (CVE-2024-12397), a panic issue in crypto/x509 when parsing partial PKCS1 private keys (CVE-2025-22866), a native crash vulnerability in io. netty's SslHandler (CVE-2025-24970), and a potential denial of service via stack exhaustion in json-smart (CVE-2024-57699). The update aims to improve security and stability. Red Hat rates this update as important and recommends applying it after ensuring all prior relevant errata are installed. Join the discussion | GCVE Database | 06/10/2025, 10:39:32 UTC Added: 06/02/2026, 21:43:30 UTC |
Red Hat Security Advisory: OpenShift Container Platform 4.17.15 security and extras updateCVE-2024-21538 0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.17.15. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2025:0876 Security Fix(es): * golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) * body-parser: Denial of Service Vulnerability in body-parser (CVE-2024-45590) * dompurify: DOMPurify vulnerable to tampering by prototype pollution (CVE-2024-48910) * jinja2: Jinja has a sandbox breakout through malicious filenames (CVE-2024-56201) * express: Improper Input Handling in Express Redirects (CVE-2024-43796) * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) * path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) * path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x (CVE-2024-52798) * nanoid: nanoid mishandles non-integer values (CVE-2024-55565) * jinja2: Jinja has a sandbox breakout through indirect reference to format method (CVE-2024-56326) * cross-spawn: regular expression denial of service (CVE-2024-21538) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.17/updating/updating_a_cluster/updating-cluster-cli.html Join the discussion | GCVE Database | 02/05/2025, 10:48:52 UTC Added: 05/28/2026, 22:15:03 UTC |
Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.0.6CVE-2024-45338 0 Logging for Red Hat OpenShift - 6.0.6 lokistack-gateway-container: Go JOSE's Parsing Vulnerable to Denial of Service (CVE-2025-27144) logging-loki-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338) Join the discussion | GCVE Database | 03/26/2025, 17:34:00 UTC Added: 05/26/2026, 20:58:49 UTC |
Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.1 release.CVE-2024-45338 0 Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins. Join the discussion | GCVE Database | 01/20/2025, 12:54:15 UTC Added: 05/26/2026, 20:58:24 UTC |
Showing 1 to 5 of 5 results