Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:3316", "cpe": "cpe:/a:redhat:migration_toolkit_applications:7.0::el9", "package": "mta/mta-analyzer-addon-rhel9:7.0.3-13", "product_name": "MTA-7.0-RHEL-9", "release_date": "2024-05-23T00:00:00Z"}, {"advisory": "RHSA-2024:3316", "cpe": "cpe:/a:redhat:migration_toolkit_applications:7.0::el9", "package": "mta/mta-hub-rhel9:7.0.3-10", "product_name": "MTA-7.0-RHEL-9", "release_date": "2024-05-23T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-agent-rhel8:1.57.0-5", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-all-in-one-rhel8:1.57.0-5", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-collector-rhel8:1.57.0-5", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-es-index-cleaner-rhel8:1.57.0-6", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-es-rollover-rhel8:1.57.0-6", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-ingester-rhel8:1.57.0-5", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-operator-bundle:1.57.0-20", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-query-rhel8:1.57.0-5", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/jaeger-rhel8-operator:1.57.0-5", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/opentelemetry-collector-rhel8:0.100.1-4", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/opentelemetry-operator-bundle:0.100.1-9", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/opentelemetry-rhel8-operator:0.100.1-3", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/opentelemetry-target-allocator-rhel8:0.100.1-3", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/tempo-gateway-opa-rhel8:1.0.0-9", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/tempo-gateway-rhel8:1.0.0-8", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/tempo-operator-bundle:0.10.0-20", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/tempo-query-rhel8:0.10.0-8", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/tempo-rhel8:2.4.2-3", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}, {"advisory": "RHSA-2024:3621", "cpe": "cpe:/a:redhat:openshift_distributed_tracing:3.2::el8", "package": "rhosdt/tempo-rhel8-operator:0.10.0-6", "product_name": "Red Hat Openshift distributed tracing 3.2", "release_date": "2024-06-05T00:00:00Z"}], "bugzilla": {"description": "go-resty: HTTP request body disclosure in github.com/go-resty/resty/v2", "id": "2252012", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2252012"}, "csaw": false, "cvss3": {"cvss3_base_score": "4.7", "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N", "status": "verified"}, "cwe": "CWE-362", "details": ["A race condition in go-resty can result in HTTP request body disclosure across requests. This condition can be triggered by calling sync.Pool.Put with the same *bytes.Buffer more than once, when request retries are enabled and a retry occurs. The call to sync.Pool.Get will then return a bytes.Buffer that hasn't had bytes.Buffer.Reset called on it. This dirty buffer will contain the HTTP request body from an unrelated request, and go-resty will append the current HTTP request body to it, sending two bodies in one request. The sync.Pool in question is defined at package level scope, so a completely unrelated server could receive the request body."], "name": "CVE-2023-45286", "package_state": [{"cpe": "cpe:/a:redhat:migration_toolkit_applications:6", "fix_state": "Will not fix", "package_name": "mta/mta-hub-rhel8", "product_name": "Migration Toolkit for Applications 6"}, {"cpe": "cpe:/a:redhat:migration_toolkit_applications:6", "fix_state": "Will not fix", "package_name": "mta/mta-windup-addon-rhel9", "product_name": "Migration Toolkit for Applications 6"}, {"cpe": "cpe:/a:redhat:ceph_storage:5", "fix_state": "Not affected", "package_name": "rhceph/rhceph-5-dashboard-rhel8", "product_name": "Red Hat Ceph Storage 5"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/ose-prometheus", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/ose-prom-label-proxy", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift_devspaces:3:", "fix_state": "Not affected", "package_name": "devspaces/traefik-rhel8", "product_name": "Red Hat OpenShift Dev Spaces"}, {"cpe": "cpe:/a:redhat:openshift_distributed_tracing:2", "fix_state": "Affected", "package_name": "rhosdt/opentelemetry-rhel8-operator", "product_name": "Red Hat OpenShift distributed tracing 2"}, {"cpe": "cpe:/a:redhat:openshift_distributed_tracing:2", "fix_state": "Affected", "package_name": "rhosdt/tempo-gateway-rhel8", "product_name": "Red Hat OpenShift distributed tracing 2"}], "public_date": "2023-11-28T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2023-45286\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-45286"], "threat_severity": "Moderate"}