Resource exhaustion in go-jose - CVE-2024-28180
Published: March 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when decompressing JWE with Decrypt or DecryptMulti. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Fedora
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Containers Module
HPC Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Agent
Storage Ceph
PowerStore T
EMC Cloud Tiering Appliance
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
buildah
Red Hat OpenShift Container Platform
Container Projects skopeo
OpenShift Service Mesh
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
Consul
IBM Concert Software
Red Hat Advanced Cluster Management for Kubernetes
Custom Metrics Autoscaler Operator for Red Hat OpenShift
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM MQ Operator
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Splunk Enterprise
QRadar Suite
Splunk Universal Forwarder
toolbox-tests
toolbox
udica
conmon-rs (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
butane (Red Hat package)
podman-tui
skopeo-debuginfo
skopeo
containers-common
skopeo-debugsource
runc (Red Hat package)
runc
slirp4netns
oci-seccomp-bpf-hook
apptainer
apptainer-sle15_7
apptainer-leap
apptainer-sle15_5
apptainer-sle15_6
apptainer-debuginfo
containernetworking-plugins (Red Hat package)
containernetworking-plugins
skopeo (Red Hat package)
aardvark-dns
netavark
prometheus-podman-exporter
fuse-overlayfs
crun
skopeo-tests
skopeo-fish-completion
skopeo-bash-completion
skopeo-zsh-completion
cri-o-debugsource
cri-o
cri-o-debuginfo
buildah (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
libgpg-error0-32bit-debuginfo
libgpg-error0-32bit
libgpg-error-devel-debuginfo
libgpg-error-debugsource
libgpg-error0-debuginfo
libgpg-error0
libgpg-error-devel
buildah
buildah-tests
conmon (Red Hat package)
conmon
golang-github-letsencrypt-pebble
caddy
ignition (Red Hat package)
container-selinux
kata-containers (Red Hat package)
singularity-ce
python3-criu
criu-devel
crit
criu
criu-libs
podman (Red Hat package)
libslirp
libslirp-devel
libslirp (Red Hat package)
python3-podman
podman-plugins
podman
podman-tests
podman-remote
podman-catatonit
podman-docker
podman-gvproxy
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
openshift4-aws-iso (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
ose-azure-acr-image-credential-provider (Red Hat package)
ose-gcp-gcr-image-credential-provider (Red Hat package)
golang-github-acme-lego
kernel (Red Hat package)
kernel-rt (Red Hat package)
python-sushy-oem-idrac (Red Hat package)
grafana
grafana-debuginfo
ovn23.06 (Red Hat package)
docker-zsh-completion
docker-bash-completion
docker-fish-completion
docker-rootless-extras
docker-debuginfo
docker
cockpit-podman
rpm-ostree (Red Hat package)
IBM DB2
How to mitigate CVE-2024-28180
Agent - update to 0.40.4
OpenShift API for Data Protection (OADP) - update to 1.3.1
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.4
Container Projects skopeo - update to 1.14.4
Consul - update to 1.18.2
buildah - update to 1.33.8
OpenShift Service Mesh - update to 2.5.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.54, 4.12.57, 4.12.58, 4.12.60, 4.13.45, 4.14.19, 4.14.21, 4.14.23, 4.14.26, 4.14.28, 4.14.31, 4.14.39, 4.15.6, 4.15.9, 4.15.12, 4.15.13, 4.15.14, 4.15.15, 4.15.19, 4.15.35, 4.15.37, 4.16.0, 4.16.13, 4.16.18, 4.17.0, 4.17.2
Storage Ceph - update to 7.1z3
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Splunk Enterprise - addressed in versions 9.1.6, 9.1.9, 9.2.3, 9.2.6, 9.3.1, 9.3.4, 9.4.2
Splunk Universal Forwarder - addressed in versions 9.1.9, 9.2.6, 9.3.4, 9.4.2
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
conmon-rs (Red Hat package) - addressed in versions 0.5.1-4.rhaos4.12.el8, 0.5.1-4.rhaos4.12.el9, 0.5.1-6.rhaos4.13.el8, 0.5.1-6.rhaos4.13.el9, 0.6.3-1.rhaos4.15.el8, 0.6.3-1.rhaos4.15.el9
golang-github-prometheus-promu (Red Hat package) - update to 0.15.0-15.3.gitd5383c5.el8
butane (Red Hat package) - addressed in versions 0.16.0-2.2.rhaos4.12.el8, 0.19.0-1.3.rhaos4.14.el8, 0.20.0-1.1.rhaos4.15.el8
podman-tui - addressed in versions 0.18.0-1.el9, 0.18.0-1.fc38, 0.18.0-1.fc39, 0.18.0-1.fc40, 1.0.0-1.el9, 1.0.0-1.fc38, 1.0.0-1.fc39, 1.0.0-1.fc40
IBM Concert Software - update to 1.0.1
skopeo-debuginfo - addressed in versions 1.1.0-12, 1.5.2-6, 1.5.2-7, 1.8.0-5
skopeo - addressed in versions 1.1.0-12, 1.5.2-6, 1.5.2-7, 1.8.0-5
containers-common - addressed in versions 1.1.0-12, 1.5.2-6, 1.5.2-7
skopeo-debugsource - addressed in versions 1.1.0-12, 1.5.2-6, 1.5.2-7, 1.8.0-5
runc (Red Hat package) - addressed in versions 1.1.6-5.2.rhaos4.12.el8, 1.1.12-1.1.rhaos4.14.el8, 1.1.12-1.1.rhaos4.15.el8, 1.1.12-1.1.rhaos4.15.el9, 1.1.12-1.2.rhaos4.13.el8
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
apptainer - addressed in versions 1.3.0-1.el7, 1.3.0-1.el8, 1.3.0-1.el9, 1.3.0-1.fc39, 1.3.0-1.fc40
apptainer-sle15_7 - update to 1.3.6-150600.4.3.1
apptainer-leap - update to 1.3.6-150600.4.3.1
apptainer-sle15_5 - update to 1.3.6-150600.4.3.1
apptainer-sle15_6 - update to 1.3.6-150600.4.3.1
apptainer - update to 1.3.6-150600.4.3.1
apptainer-debuginfo - update to 1.3.6-150600.4.3.1
containernetworking-plugins (Red Hat package) - addressed in versions 1.4.0-1.1.rhaos4.12.el8, 1.4.0-1.2.rhaos4.13.el8, 1.4.0-1.2.rhaos4.14.el8, 1.4.0-1.2.rhaos4.15.el8
containernetworking-plugins - update to 1.4.0-2.0.1
skopeo (Red Hat package) - addressed in versions 1.9.4-3.2.rhaos4.12.el8, 1.9.4-3.2.rhaos4.12.el9, 1.11.2-10.3.rhaos4.14.el8, 1.11.2-10.3.rhaos4.14.el9, 1.11.2-21.2.rhaos4.15.el8, 1.11.2-21.2.rhaos4.15.el9, 1.11.3-0.1.rhaos4.15.el8, 1.11.3-0.1.rhaos4.15.el9, 1.11.3-0.2.rhaos4.13.el8, 1.11.3-0.2.rhaos4.13.el9, 1.14.3-2.el9_4
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
QRadar Suite - update to 1.10.22.0
prometheus-podman-exporter - addressed in versions 1.11.0-1.el9, 1.11.0-1.fc38, 1.11.0-1.fc39, 1.11.0-1.fc40
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo - update to 1.14.3-2.0.1
skopeo-tests - update to 1.14.3-2.0.1
skopeo - addressed in versions 1.14.4-150000.4.26.1, 1.14.4-150300.11.11.1
skopeo-debuginfo - addressed in versions 1.14.4-150000.4.26.1, 1.14.4-150300.11.11.1
skopeo-fish-completion - update to 1.14.4-150300.11.11.1
skopeo-bash-completion - update to 1.14.4-150300.11.11.1
skopeo-zsh-completion - update to 1.14.4-150300.11.11.1
cri-o-debugsource - update to 1.23.2-11
cri-o - update to 1.23.2-11
cri-o-debuginfo - update to 1.23.2-11
buildah (Red Hat package) - addressed in versions 1.23.4-5.2.rhaos4.12.el8, 1.23.4-5.2.rhaos4.12.el9, 1.29.1-2.3.rhaos4.13.el8, 1.29.1-10.3.rhaos4.14.el8, 1.29.1-20.3.rhaos4.15.el8, 1.29.1-20.3.rhaos4.15.el9, 1.33.7-2.el9_4
cri-tools (Red Hat package) - addressed in versions 1.25.0-2.2.el8, 1.25.0-2.2.el9, 1.26.0-4.2.el8, 1.26.0-4.3.el9, 1.27.0-3.1.el8, 1.27.0-3.1.el9, 1.28.0-3.1.el8, 1.28.0-3.1.el9
cri-o (Red Hat package) - addressed in versions 1.25.3-5.2.rhaos4.12.git44a2cb2.el9, 1.25.5-13.1.rhaos4.12.git76343da.el8, 1.26.5-10.rhaos4.13.gita08b329.el8, 1.26.5-10.rhaos4.13.gita08b329.el9, 1.26.5-11.2.rhaos4.13.git919cc6e.el8, 1.26.5-11.2.rhaos4.13.git919cc6e.el9, 1.26.5-15.2.rhaos4.13.gitb742e63.el8, 1.26.5-15.2.rhaos4.13.gitb742e63.el9, 1.27.4-6.1.rhaos4.14.gitd09e4c0.el8, 1.27.4-6.1.rhaos4.14.gitd09e4c0.el9, 1.27.6-2.rhaos4.14.gitb3bd0bf.el8, 1.27.6-2.rhaos4.14.gitb3bd0bf.el9, 1.28.4-8.rhaos4.15.git24f50b9.el8, 1.28.4-8.rhaos4.15.git24f50b9.el9, 1.28.5-2.rhaos4.15.git108c065.el8, 1.28.5-2.rhaos4.15.git108c065.el9, 1.28.6-5.rhaos4.15.gita02fb1e.el8, 1.28.6-5.rhaos4.15.gita02fb1e.el9
libgpg-error0-32bit-debuginfo - update to 1.29-150000.3.3.1
libgpg-error0-32bit - update to 1.29-150000.3.3.1
libgpg-error-devel-debuginfo - update to 1.29-150000.3.3.1
libgpg-error-debugsource - update to 1.29-150000.3.3.1
libgpg-error0-debuginfo - update to 1.29-150000.3.3.1
libgpg-error0 - update to 1.29-150000.3.3.1
libgpg-error-devel - update to 1.29-150000.3.3.1
Red Hat OpenShift Serverless - update to 1.33.0
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
buildah - addressed in versions 1.35.4-150300.8.25.1, 1.35.4-150400.3.30.1, 1.35.4-150500.3.10.1
containers-common - update to 1-81.0.1
conmon (Red Hat package) - addressed in versions 2.1.2-5.2.rhaos4.12.el8, 2.1.2-6.2.rhaos4.12.el9, 2.1.7-2.3.rhaos4.13.el8, 2.1.7-2.3.rhaos4.13.el9, 2.1.7-3.3.rhaos4.14.el8, 2.1.7-3.3.rhaos4.14.el9, 2.1.7-6.rhaos4.15.el8, 2.1.7-10.1.rhaos4.15.el9, 2.1.7-11.2.rhaos4.15.el9
conmon - update to 2.1.10-1
golang-github-letsencrypt-pebble - update to 2.6.0-1.fc42
caddy - update to 2.8.4-1.fc41
Red Hat Advanced Cluster Management for Kubernetes - update to 2.12.0
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
ignition (Red Hat package) - addressed in versions 2.14.0-5.2.rhaos4.12.el9, 2.14.0-7.1.rhaos4.12.el8, 2.15.0-7.2.rhaos4.13.el9, 2.16.2-2.1.rhaos4.14.el9, 2.16.2-2.1.rhaos4.15.el9
container-selinux - update to 2.229.0-2
kata-containers (Red Hat package) - update to 3.2.0-4.rhaos4.13.el9
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00
PowerStoreX OS - update to 3.2.1.5-2424458
PowerStore T - update to 3.6.1.4-2413340
singularity-ce - addressed in versions 3.11.5^20240603gbd4675f-1.fc39, 4.1.3-1.el8
python3-criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
podman (Red Hat package) - addressed in versions 4.2.0-7.2.rhaos4.12.el9, 4.4.1-2.1.rhaos4.12.el8, 4.4.1-5.3.rhaos4.13.el8, 4.4.1-6.3.rhaos4.13.el9, 4.4.1-7.3.rhaos4.13.el8, 4.4.1-8.3.rhaos4.13.el9, 4.4.1-11.3.rhaos4.14.el8, 4.4.1-11.3.rhaos4.14.el9, 4.4.1-13.4.rhaos4.14.el8, 4.4.1-13.4.rhaos4.14.el9, 4.4.1-21.1.rhaos4.15.el8, 4.4.1-21.1.rhaos4.15.el9, 4.9.4-4.el9_4
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
libslirp (Red Hat package) - addressed in versions 4.4.0-4.rhaos4.12.el8, 4.4.0-4.rhaos4.13.el8
python3-podman - update to 4.9.0-1
podman-plugins - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
openshift-ansible (Red Hat package) - addressed in versions 4.12.0-202403201504.p0.gd97dd6f.assembly.stream.el8, 4.13.0-202404151710.p0.g2d540c5.assembly.stream.el8, 4.13.0-202404151710.p0.g2d540c5.assembly.stream.el9, 4.14.0-202403201503.p0.g81558cc.assembly.stream.el8, 4.14.0-202403201503.p0.g81558cc.assembly.stream.el9, 4.15.0-202403201503.p0.g1c9b99e.assembly.stream.el8, 4.15.0-202403201503.p0.g1c9b99e.assembly.stream.el9, 4.15.0-202404191246.p0.g54692e9.assembly.stream.el8, 4.15.0-202404191246.p0.g54692e9.assembly.stream.el9
openshift-kuryr (Red Hat package) - addressed in versions 4.12.0-202403201504.p0.g8fd2f8b.assembly.stream.el8, 4.13.0-202404151710.p0.g36754b7.assembly.stream.el8, 4.14.0-202403201503.p0.g8926a29.assembly.stream.el8
openshift4-aws-iso (Red Hat package) - addressed in versions 4.12.0-202403201504.p0.gd2acdd5.assembly.stream.el8, 4.13.0-202404151710.p0.gd2acdd5.assembly.stream.el8, 4.14.0-202403201503.p0.gd2acdd5.assembly.stream.el8, 4.15.0-202403201503.p0.gd2acdd5.assembly.stream.el8
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el8, 4.12.0-202403251017.p0.gd4c9e3c.assembly.stream.el9, 4.13.0-202404151710.p0.gd192e90.assembly.stream.el8, 4.13.0-202404151710.p0.gd192e90.assembly.stream.el9, 4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el8, 4.14.0-202403261640.p0.gf7b14a9.assembly.stream.el9, 4.15.0-202403211240.p0.g62c4d45.assembly.stream.el8, 4.15.0-202403211240.p0.g62c4d45.assembly.stream.el9, 4.15.0-202405021207.p0.g7693229.assembly.stream.el8, 4.15.0-202405021207.p0.g7693229.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.12.0-202403251017.p0.g9946c63.assembly.stream.el8, 4.12.0-202403251017.p0.g9946c63.assembly.stream.el9, 4.13.0-202403081338.p0.g03ee898.assembly.stream.el8, 4.13.0-202403081338.p0.g03ee898.assembly.stream.el9, 4.13.0-202404222036.p0.g4818370.assembly.stream.el8, 4.13.0-202404222036.p0.g4818370.assembly.stream.el9, 4.14.0-202403251040.p0.g749fe1d.assembly.stream.el8, 4.14.0-202403251040.p0.g749fe1d.assembly.stream.el9, 4.14.0-202404301807.p0.gfd36fb9.assembly.stream.el8, 4.14.0-202404301807.p0.gfd36fb9.assembly.stream.el9, 4.15.0-202403211549.p0.gf1b5f6c.assembly.stream.el8, 4.15.0-202403211549.p0.gf1b5f6c.assembly.stream.el9, 4.15.0-202404230312.p0.g2f7b992.assembly.stream.el8, 4.15.0-202404230312.p0.g2f7b992.assembly.stream.el9, 4.15.0-202405030637.p0.g8ca71f7.assembly.stream.el8, 4.15.0-202405030637.p0.g8ca71f7.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - addressed in versions 4.14.0-202403251040.p0.g607e2dd.assembly.stream.el8, 4.14.0-202403251040.p0.g607e2dd.assembly.stream.el9, 4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el8, 4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el9, 4.15.0-202404241208.p0.gb88529a.assembly.stream.el8, 4.15.0-202404241208.p0.gb88529a.assembly.stream.el9
ose-azure-acr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202404181743.p0.ge8055fe.assembly.stream.el8, 4.15.0-202404181743.p0.ge8055fe.assembly.stream.el9
ose-gcp-gcr-image-credential-provider (Red Hat package) - addressed in versions 4.15.0-202404181743.p0.gfc50272.assembly.stream.el8, 4.15.0-202404181743.p0.gfc50272.assembly.stream.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.16.0
golang-github-acme-lego - update to 4.17.4-4.fc41
kernel (Red Hat package) - addressed in versions 4.18.0-372.98.1.el8_6, 5.14.0-284.64.1.el9_2, 5.14.0-284.66.1.el9_2
kernel-rt (Red Hat package) - addressed in versions 4.18.0-372.98.1.rt7.258.el8_6, 5.14.0-284.64.1.rt14.349.el9_2, 5.14.0-284.66.1.rt14.351.el9_2
IBM DB2 - update to 5.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.1
python-sushy-oem-idrac (Red Hat package) - update to 5.0.1-0.20240423161024.4e51aef.el9
IBM MQ Operator - addressed in versions 9.3.0.20-r2, 9.4.0.0-r3
grafana - addressed in versions 10.4.15-1.71.1, 10.4.15-150000.1.71.1, 10.4.15-150200.3.64.1
grafana-debuginfo - addressed in versions 10.4.15-150000.1.71.1, 10.4.15-150200.3.64.1
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
ovn23.06 (Red Hat package) - update to 23.06.3-29.el9fdp
docker-zsh-completion - update to 25.0.6_ce-150000.207.1
docker-bash-completion - update to 25.0.6_ce-150000.207.1
docker-fish-completion - update to 25.0.6_ce-150000.207.1
docker-rootless-extras - update to 25.0.6_ce-150000.207.1
docker-debuginfo - update to 25.0.6_ce-150000.207.1
docker - update to 25.0.6_ce-150000.207.1
cockpit-podman - update to 84.1-1
rpm-ostree (Red Hat package) - update to 2024.3-3.el9_4
External References
- https://github.com/go-jose/go-jose/security/advisories/GHSA-c5q2-7r4c-mv6g
- https://github.com/go-jose/go-jose/commit/0dd4dd541c665fb292d664f77604ba694726f298
- https://github.com/go-jose/go-jose/commit/add6a284ea0f844fd6628cba637be5451fe4b28a
- https://github.com/go-jose/go-jose/commit/f4c051a0653d78199a053892f7619ebf96339502
Related Security Bulletins
- Fedora EPEL 7 update for apptainer
- Fedora 39 update for apptainer
- Denial of service in JOSE for Go
- Fedora EPEL 8 update for apptainer
- Fedora 40 update for apptainer
- Fedora EPEL 9 update for apptainer
- Fedora 38 update for podman-tui
- Fedora 40 update for podman-tui
- Fedora EPEL 9 update for podman-tui
- Fedora 39 update for podman-tui
- Fedora 40 update for podman-tui
- Fedora EPEL 9 update for podman-tui
- Fedora 38 update for podman-tui
- Fedora 39 update for podman-tui
- Fedora EPEL 9 update for prometheus-podman-exporter
- Fedora 38 update for prometheus-podman-exporter
- Fedora 39 update for prometheus-podman-exporter
- Fedora 40 update for prometheus-podman-exporter
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 for RHEL 9 and 8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Agent
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- openEuler 22.03 LTS SP1 update for cri-o
- openEuler 22.03 LTS SP2 update for cri-o
- openEuler 22.03 LTS SP3 update for cri-o
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Red Hat Enterprise Linux 9 update for skopeo
- Multiple vulnerabilities in HashiCorp Consul
- openEuler 22.03 LTS SP1 update for skopeo
- openEuler 22.03 LTS SP2 update for skopeo
- Multiple vulnerabilities in Container Projects skopeo
- Fedora EPEL 8 update for singularity-ce
- Fedora 39 update for singularity-ce
- openEuler 22.03 LTS SP3 update for skopeo
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- SUSE update for skopeo
- Red Hat Enterprise Linux 9 update for podman
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Resource exhaustion in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Resource exhaustion in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- Resource exhaustion in Red Hat OpenShift Container Platform 4.14
- Resource exhaustion in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.33
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Fedora 41 update for caddy
- SUSE update for skopeo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Fedora 41 update for golang-github-acme-lego
- SUSE update for skopeo
- Denial of service in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM MQ Operator
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Concert Software
- Fedora 42 update for golang-github-letsencrypt-pebble
- SUSE update for buildah, docker
- SUSE update for buildah
- SUSE update for buildah
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Containers Buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Dell PowerStore T
- SUSE update for apptainer
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- SUSE update for grafana
- SUSE update for grafana
- SUSE update for grafana
- Anolis OS update for container-tools:an8 module
- Anolis OS update for container-tools:an8 module
- Multiple vulnerabilities in Dell PowerStore X
- Splunk Universal Forwarder update for third-party components
- Splunk Enterprise update for third-party components
- openEuler 20.03 LTS SP4 update for skopeo
- IBM Storage Ceph update for Go-Jose in Grafana