Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-central-db-rhel8:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-collector-rhel8:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-collector-slim-rhel8:4.3.5-1", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-main-rhel8:4.3.5-4", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-operator-bundle:4.3.5-4", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-rhel8-operator:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-roxctl-rhel8:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-scanner-db-rhel8:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.3.5-1", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-scanner-rhel8:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}, {"advisory": "RHSA-2024:1321", "cpe": "cpe:/a:redhat:advanced_cluster_security:4.3::el8", "package": "advanced-cluster-security/rhacs-scanner-slim-rhel8:4.3.5-3", "product_name": "Red Hat Advanced Cluster Security 4.3", "release_date": "2024-03-13T00:00:00Z"}], "bugzilla": {"description": "pgx: SQL Injection via Protocol Message Size Overflow", "id": "2268269", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268269"}, "csaw": false, "cvss3": {"cvss3_base_score": "8.1", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-89", "details": ["pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size."], "name": "CVE-2024-27304", "package_state": [{"cpe": "cpe:/a:redhat:migration_toolkit_applications:6", "fix_state": "Will not fix", "package_name": "mta/mta-hub-rhel8", "product_name": "Migration Toolkit for Applications 6"}, {"cpe": "cpe:/a:redhat:migration_toolkit_applications:6", "fix_state": "Will not fix", "package_name": "mta/mta-windup-addon-rhel9", "product_name": "Migration Toolkit for Applications 6"}, {"cpe": "cpe:/a:redhat:multicluster_engine", "fix_state": "Not affected", "package_name": "multicluster-engine/agent-service-rhel8", "product_name": "Multicluster Engine for Kubernetes"}, {"cpe": "cpe:/a:redhat:multicluster_engine", "fix_state": "Not affected", "package_name": "multicluster-engine/assisted-installer-agent-rhel8", "product_name": "Multicluster Engine for Kubernetes"}, {"cpe": "cpe:/a:redhat:multicluster_engine", "fix_state": "Not affected", "package_name": "multicluster-engine/assisted-installer-reporter-rhel8", "product_name": "Multicluster Engine for Kubernetes"}, {"cpe": "cpe:/a:redhat:multicluster_engine", "fix_state": "Not affected", "package_name": "multicluster-engine/assisted-installer-rhel8", "product_name": "Multicluster Engine for Kubernetes"}, {"cpe": "cpe:/a:redhat:acm:2", "fix_state": "Not affected", "package_name": "rhacm2/acm-search-indexer-rhel8", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2"}, {"cpe": "cpe:/a:redhat:acm:2", "fix_state": "Not affected", "package_name": "rhacm2/acm-search-v2-api-rhel8", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2"}, {"cpe": "cpe:/a:redhat:advanced_cluster_security:3", "fix_state": "Out of support scope", "package_name": "advanced-cluster-security/rhacs-central-db-rhel8", "product_name": "Red Hat Advanced Cluster Security 3"}, {"cpe": "cpe:/a:redhat:advanced_cluster_security:3", "fix_state": "Out of support scope", "package_name": "advanced-cluster-security/rhacs-main-rhel8", "product_name": "Red Hat Advanced Cluster Security 3"}, {"cpe": "cpe:/a:redhat:advanced_cluster_security:3", "fix_state": "Out of support scope", "package_name": "advanced-cluster-security/rhacs-rhel8-operator", "product_name": "Red Hat Advanced Cluster Security 3"}, {"cpe": "cpe:/a:redhat:advanced_cluster_security:3", "fix_state": "Out of support scope", "package_name": "advanced-cluster-security/rhacs-roxctl-rhel8", "product_name": "Red Hat Advanced Cluster Security 3"}, {"cpe": "cpe:/a:redhat:ansible_automation_platform:2", "fix_state": "Will not fix", "package_name": "aap-cloud-ui-container", "product_name": "Red Hat Ansible Automation Platform 2"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Will not fix", "package_name": "osbuild-composer", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Will not fix", "package_name": "osbuild-composer", "product_name": "Red Hat Enterprise Linux 9"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Affected", "package_name": "openshift4/ose-agent-installer-api-server-rhel9", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Affected", "package_name": "openshift4/ose-agent-installer-csr-approver-rhel8", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Affected", "package_name": "openshift4/ose-agent-installer-node-agent-rhel9", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Affected", "package_name": "openshift4/ose-agent-installer-orchestrator-rhel8", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:assisted_installer:", "fix_state": "Affected", "package_name": "rhai-tech-preview/assisted-installer-agent-rhel8", "product_name": "Red Hat OpenShift Container Platform Assisted Installer"}, {"cpe": "cpe:/a:redhat:assisted_installer:", "fix_state": "Affected", "package_name": "rhai-tech-preview/assisted-installer-reporter-rhel8", "product_name": "Red Hat OpenShift Container Platform Assisted Installer"}, {"cpe": "cpe:/a:redhat:assisted_installer:", "fix_state": "Affected", "package_name": "rhai-tech-preview/assisted-installer-rhel8", "product_name": "Red Hat OpenShift Container Platform Assisted Installer"}, {"cpe": "cpe:/a:redhat:openshift_container_storage:4", "fix_state": "Affected", "package_name": "ocs4/cephcsi-rhel8", "product_name": "Red Hat Openshift Container Storage 4"}, {"cpe": "cpe:/a:redhat:openshift_container_storage:4", "fix_state": "Affected", "package_name": "ocs4/mcg-rhel8-operator", "product_name": "Red Hat Openshift Container Storage 4"}, {"cpe": "cpe:/a:redhat:openshift_container_storage:4", "fix_state": "Affected", "package_name": "ocs4/ocs-must-gather-rhel8", "product_name": "Red Hat Openshift Container Storage 4"}, {"cpe": "cpe:/a:redhat:openshift_container_storage:4", "fix_state": "Affected", "package_name": "ocs4/ocs-rhel8-operator", "product_name": "Red Hat Openshift Container Storage 4"}, {"cpe": "cpe:/a:redhat:openshift_data_foundation:4", "fix_state": "Not affected", "package_name": "odf4/rook-ceph-rhel8-operator", "product_name": "Red Hat Openshift Data Foundation 4"}, {"cpe": "cpe:/a:redhat:openshift_data_science", "fix_state": "Affected", "package_name": "rhods/odh-ml-pipelines-api-server-rhel8", "product_name": "Red Hat OpenShift Data Science (RHODS)"}, {"cpe": "cpe:/a:redhat:openshift_data_science", "fix_state": "Affected", "package_name": "rhods/odh-ml-pipelines-artifact-manager-rhel8", "product_name": "Red Hat OpenShift Data Science (RHODS)"}, {"cpe": "cpe:/a:redhat:openshift_data_science", "fix_state": "Affected", "package_name": "rhods/odh-ml-pipelines-cache-rhel8", "product_name": "Red Hat OpenShift Data Science (RHODS)"}, {"cpe": "cpe:/a:redhat:openshift_data_science", "fix_state": "Affected", "package_name": "rhods/odh-ml-pipelines-persistenceagent-rhel8", "product_name": "Red Hat OpenShift Data Science (RHODS)"}, {"cpe": "cpe:/a:redhat:openshift_data_science", "fix_state": "Affected", "package_name": "rhods/odh-ml-pipelines-scheduledworkflow-rhel8", "product_name": "Red Hat OpenShift Data Science (RHODS)"}, {"cpe": "cpe:/a:redhat:openshift_data_science", "fix_state": "Affected", "package_name": "rhods/odh-operator-base-rhel8", "product_name": "Red Hat OpenShift Data Science (RHODS)"}, {"cpe": "cpe:/a:redhat:openshift_service_on_aws:1", "fix_state": "Affected", "package_name": "rosa", "product_name": "Red Hat OpenShift on AWS"}, {"cpe": "cpe:/a:redhat:openstack:16.2", "fix_state": "Will not fix", "package_name": "osp-director-provisioner-container", "product_name": "Red Hat OpenStack Platform 16.2"}, {"cpe": "cpe:/a:redhat:quay:3", "fix_state": "Affected", "package_name": "quay/clair-rhel8", "product_name": "Red Hat Quay 3"}, {"cpe": "cpe:/a:redhat:quay:3", "fix_state": "Affected", "package_name": "quay/quay-operator-rhel8", "product_name": "Red Hat Quay 3"}, {"cpe": "cpe:/a:redhat:quay:3", "fix_state": "Affected", "package_name": "quay/quay-rhel8", "product_name": "Red Hat Quay 3"}], "public_date": "2024-03-06T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2024-27304\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-27304"], "threat_severity": "Moderate"}