drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in discovery container images
| Name: |
Zwei Probleme in discovery container images |
|
| ID: |
RHSA-2025:3709 |
|
| Distribution: |
Red Hat |
|
| Plattformen: |
Red Hat Discovery 1 for RHEL 9 |
|
| Datum: |
Di, 8. April 2025, 22:24 |
|
| Referenzen: |
https://access.redhat.com/security/cve/CVE-2025-26699
https://access.redhat.com/errata/RHSA-2025:3709
https://access.redhat.com/security/cve/CVE-2024-6827
https://issues.redhat.com/browse/DISCOVERY-924 |
|
| Applikationen: |
discovery container images |
|
Originalnachricht |
Updated container images are now available for Discovery 1.13.1.
The Discovery container images provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References).
This release resolves the following CVEs:
* discovery-server-container: HTTP Request Smuggling in benoitc/gunicorn (CVE-2025-26699) * discovery-server-container: Potential denial-of-service vulnerability in django.utils.text.wrap() (CVE-2024-6827)
Dockerfiles and scripts should be amended either to refer to these new images specifically, or to the latest images generally.
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2024-6827: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') (CWE-444) CVE-2025-26699: Uncontrolled Resource Consumption (CWE-400)
|
|
|
|