Resource exhaustion in jose - CVE-2024-28176
Published: March 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the JSON Web Encryption (JWE) decryption interfaces. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM Concert Software
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Maximo Application Suite
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Event Streams
toolbox-tests
toolbox
toolbox (Red Hat package)
udica
conmon-rs (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
podman-tui
butane (Red Hat package)
slirp4netns (Red Hat package)
runc
runc (Red Hat package)
slirp4netns
oci-seccomp-bpf-hook
apptainer
containernetworking-plugins
containernetworking-plugins (Red Hat package)
aardvark-dns
fuse-overlayfs (Red Hat package)
netavark
fuse-overlayfs
crun (Red Hat package)
crun
skopeo
skopeo-tests
skopeo (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
buildah (Red Hat package)
containers-common (Red Hat package)
containers-common
conmon
conmon (Red Hat package)
haproxy (Red Hat package)
ignition (Red Hat package)
container-selinux
container-selinux (Red Hat package)
criu-libs
criu-devel
criu
crit
python3-criu
libslirp-devel
libslirp
libslirp (Red Hat package)
python3-podman
podman (Red Hat package)
podman-plugins
podman-remote
podman-gvproxy
podmansh
podman-tests
podman-debugsource
podman-debuginfo
podman
podman-help
podman-docker
ose-gcp-gcr-image-credential-provider (Red Hat package)
openshift-ansible (Red Hat package)
openshift4-aws-iso (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
jose
libjose
libjose-devel
jose (Red Hat package)
ovn24.03 (Red Hat package)
cockpit-podman
ostree (Red Hat package)
IBM Planning Analytics Workspace
Security QRadar EDR
IBM Cloud Pak for Watson AIOps
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - Edge Data Collector
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM App Connect Enterprise
How to mitigate CVE-2024-28176
IBM Concert Software - update to 1.0.3
Event Streams - update to 11.3.2
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - addressed in versions 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9
udica - update to 0.2.6-21
conmon-rs (Red Hat package) - addressed in versions 0.6.3-1.rhaos4.16.el8, 0.6.3-1.rhaos4.16.el9
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-15.2.gitd5383c5.el9
podman-tui - addressed in versions 0.18.0-1.el9, 0.18.0-1.fc38, 0.18.0-1.fc39, 0.18.0-1.fc40, 1.0.0-1.el9, 1.0.0-1.fc38, 1.0.0-1.fc39, 1.0.0-1.fc40
butane (Red Hat package) - update to 0.21.0-1.rhaos4.16.el8
slirp4netns (Red Hat package) - update to 1.1.8-2.rhaos4.16.el8
runc - update to 1.1.12-1.0.1
runc (Red Hat package) - addressed in versions 1.1.12-3.1.rhaos4.16.el8, 1.1.12-3.1.rhaos4.16.el9
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
apptainer - addressed in versions 1.3.0-1.el7, 1.3.0-1.el8, 1.3.0-1.el9, 1.3.0-1.fc39, 1.3.0-1.fc40
containernetworking-plugins - update to 1.4.0-2.0.1
containernetworking-plugins (Red Hat package) - update to 1.4.0-2.1.rhaos4.16.el8
aardvark-dns - update to 1.10.0-2.0.1
fuse-overlayfs (Red Hat package) - update to 1.10-2.rhaos4.16.el8
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - addressed in versions 1.14.3-1.rhaos4.16.el8, 1.14.3-1.rhaos4.16.el9
crun - update to 1.14.3-2
skopeo - update to 1.14.3-2.0.1
skopeo-tests - update to 1.14.3-2.0.1
skopeo (Red Hat package) - addressed in versions 1.14.4-1.rhaos4.16.el8, 1.14.4-1.rhaos4.16.el9
cri-tools (Red Hat package) - addressed in versions 1.29.0-3.1.el8, 1.29.0-3.1.el9
cri-o (Red Hat package) - addressed in versions 1.29.5-5.rhaos4.16.git7032128.el8, 1.29.5-5.rhaos4.16.git7032128.el9
buildah (Red Hat package) - addressed in versions 1.33.7-1.1.rhaos4.16.el8, 1.33.7-1.1.rhaos4.16.el9, 1.33.7-2.el9_4
containers-common (Red Hat package) - addressed in versions 1-77.rhaos4.16.el8, 1-77.rhaos4.16.el9
containers-common - update to 1-81.0.1
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
conmon - update to 2.1.10-1
conmon (Red Hat package) - addressed in versions 2.1.10-2.1.rhaos4.16.el8, 2.1.10-2.1.rhaos4.16.el9
haproxy (Red Hat package) - addressed in versions 2.6.13-3.rhaos4.16.el8, 2.8.5-2.rhaos4.16.el9
ignition (Red Hat package) - update to 2.18.0-2.1.rhaos4.16.el9
container-selinux - update to 2.229.0-2
container-selinux (Red Hat package) - addressed in versions 2.231.0-1.rhaos4.16.el8, 2.231.0-1.rhaos4.16.el9
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.4
Security QRadar EDR - update to 3.12.8
criu-libs - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
libslirp (Red Hat package) - update to 4.4.0-4.rhaos4.16.el8
IBM Cloud Pak for Watson AIOps - update to 4.6.0
python3-podman - update to 4.9.0-1
podman (Red Hat package) - addressed in versions 4.9.4-4.el9_4, 4.9.4-5.1.rhaos4.16.el8, 4.9.4-5.1.rhaos4.16.el9
podman-plugins - update to 4.9.4-14
podman-remote - update to 4.9.4-14
podman-gvproxy - update to 4.9.4-14
podmansh - update to 4.9.4-14
podman-tests - update to 4.9.4-14
podman-debugsource - update to 4.9.4-14
podman-debuginfo - update to 4.9.4-14
podman - update to 4.9.4-14
podman-help - update to 4.9.4-14
podman-docker - update to 4.9.4-14
Red Hat OpenShift Container Platform - addressed in versions 4.13.46, 4.14.34, 4.16.0, 4.16.1
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.16.0, 4.16.2, 4.17.0
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.16.0-202404181812.p0.g26b43df.assembly.stream.el8, 4.16.0-202404181812.p0.g26b43df.assembly.stream.el9
openshift-ansible (Red Hat package) - addressed in versions 4.16.0-202404181812.p0.g7806532.assembly.stream.el8, 4.16.0-202404181812.p0.g7806532.assembly.stream.el9
openshift4-aws-iso (Red Hat package) - update to 4.16.0-202404181812.p0.gd2acdd5.assembly.stream.el8
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.16.0-202404301345.p0.g0e95532.assembly.stream.el8, 4.16.0-202404301345.p0.g0e95532.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.16.0-202405311136.p0.ga53e9de.assembly.stream.el8, 4.16.0-202405311136.p0.ga53e9de.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.16.0-202406052127.p0.ga245041.assembly.stream.el8, 4.16.0-202406052127.p0.ga245041.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.16.0-202406170957.p0.g29c95f3.assembly.stream.el8, 4.16.0-202406170957.p0.g29c95f3.assembly.stream.el9
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
IBM Maximo Application Suite - addressed in versions 8.10.12, 8.11.10
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.9, 9.0.1
jose - update to 10-2
libjose - update to 10-2
libjose-devel - update to 10-2
IBM App Connect Enterprise - update to 12.0.11.3
jose (Red Hat package) - update to 14-1.el9
ovn24.03 (Red Hat package) - update to 24.03.2-19.el9fdp
cockpit-podman - update to 84.1-1
ostree (Red Hat package) - update to 2024.1-2.el9
External References
Related Security Bulletins
- Denial of service in Jose
- Fedora EPEL 7 update for apptainer
- Fedora 39 update for apptainer
- Fedora EPEL 8 update for apptainer
- Fedora 40 update for apptainer
- Fedora EPEL 9 update for apptainer
- Fedora 38 update for podman-tui
- Fedora 40 update for podman-tui
- Fedora EPEL 9 update for podman-tui
- Fedora 39 update for podman-tui
- Fedora 40 update for podman-tui
- Fedora EPEL 9 update for podman-tui
- Fedora 38 update for podman-tui
- Fedora 39 update for podman-tui
- Multiple vulnerabilities in IBM App Connect Enterprise
- Resource exhaustion in IBM Event Streams
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Resource exhaustion in IBM Maximo Application Suite
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Security QRadar EDR
- Resource exhaustion in Maximo Application Suite - Edge Data Collector
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Red Hat Enterprise Linux 9 update for jose
- Multiple vulnerabilities in IBM Concert Software
- openEuler 24.03 LTS update for podman
- openEuler 24.03 LTS SP1 update for podman
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Node.js jose
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)
- Anolis OS update for container-tools:an8 module
- Anolis OS update for jose