CVE Vulnerabilities

CVE-2024-0874

Use of Cache Containing Sensitive Information

Published: Apr 25, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.

Weakness

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Software

NameVendorStart VersionEnd Version
Red Hat OpenShift Container Platform 4.13RedHatopenshift4/ose-coredns:v4.13.0-202408260940.p0.ge70f097.assembly.stream.el8*
Red Hat OpenShift Container Platform 4.14RedHatopenshift4/ose-coredns:v4.14.0-202408260910.p0.gfdd6037.assembly.stream.el8*
Red Hat OpenShift Container Platform 4.15RedHatopenshift4/ose-coredns-rhel9:v4.15.0-202407230407.p0.g1326282.assembly.stream.el9*
Red Hat OpenShift Container Platform 4.16RedHatopenshift4/ose-coredns-rhel9:v4.16.0-202406131906.p0.g04d84f7.assembly.stream.el9*

Potential Mitigations

References