Race condition in resty - CVE-2023-45286
Published: September 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a race condition. A remote attacker can exploit the race by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a retry occurs, and gain unauthorized access to sensitive information on the system.
Affected software
IBM Fusion HCI
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat Migration Toolkit for Applications
How to mitigate CVE-2023-45286
IBM Fusion HCI - update to 2.11.0
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
Red Hat Migration Toolkit for Applications - update to 7.0.3