CVE Vulnerabilities

CVE-2024-24789

Published: Jun 05, 2024 | Modified: Jul 03, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

The archive/zip packages handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

Affected Software

Name Vendor Start Version End Version
Go Golang * 1.21.11 (excluding)
Go Golang 1.22.0 (including) 1.22.4 (excluding)
OADP-1.3-RHEL-9 RedHat oadp/oadp-mustgather-rhel9:1.3.3-20 *
OADP-1.3-RHEL-9 RedHat oadp/oadp-rhel9-operator:1.3.3-12 *
OADP-1.3-RHEL-9 RedHat oadp/oadp-velero-restic-restore-helper-rhel9:1.3.3-8 *
OADP-1.3-RHEL-9 RedHat oadp/oadp-velero-rhel9:1.3.3-8 *
Openshift Serverless 1 on RHEL 8 RedHat openshift-serverless-clients-0:1.12.0-10.el8 *
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8100020240613152020.a3795dee *
Red Hat Enterprise Linux 9 RedHat golang-0:1.21.11-1.el9_4 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/client-kn-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-controller-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-istio-controller-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-controller-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-post-install-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-receiver-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-kafka-broker-webhook-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-filter-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtbroker-ingress-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtchannel-broker-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-mtping-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-storage-version-migration-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/eventing-webhook-rhel8:1.12.0-7 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/func-utils-rhel8:1.33.1-1 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/ingress-rhel8-operator:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/knative-rhel8-operator:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/kn-cli-artifacts-rhel8:1.12.0-6 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/kourier-control-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/net-istio-controller-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/net-istio-webhook-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serverless-operator-bundle:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serverless-rhel8-operator:1.33.1-2 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-activator-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-hpa-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-autoscaler-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-controller-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-queue-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-storage-version-migration-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/serving-webhook-rhel8:1.12.0-5 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1/svls-must-gather-rhel8:1.33.1-1 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1-tech-preview/backstage-plugins-eventmesh-rhel8:1.33.1-1 *
RHOSS-1.33-RHEL-8 RedHat openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8:1.12.0-6 *
Golang-1.20 Ubuntu mantic *
Golang-1.21 Ubuntu focal *
Golang-1.21 Ubuntu jammy *
Golang-1.21 Ubuntu mantic *
Golang-1.21 Ubuntu noble *
Golang-1.21 Ubuntu upstream *
Golang-1.22 Ubuntu jammy *
Golang-1.22 Ubuntu mantic *
Golang-1.22 Ubuntu noble *
Golang-1.22 Ubuntu upstream *

References