Skip to content

Commit e4343af

Browse files
committed
add CVE-2024-21538,cross-spawn,7.0.5,RHIDP-4864 to fixed payload
Signed-off-by: Nick Boldt <[email protected]>
1 parent 231b594 commit e4343af

File tree

3 files changed

+7
-7
lines changed

3 files changed

+7
-7
lines changed

assemblies/assembly-release-notes-fixed-security-issues.adoc

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ This section lists security issues fixed in {product} {product-version}.
66

77
== {product} {product-bundle-version}
88

9+
include::./modules/release-notes/snip-fixed-security-issues-in-product-1.3.2.adoc[leveloffset=+2]
10+
911
include::./modules/release-notes/snip-fixed-security-issues-in-rpm-1.3.2.adoc[leveloffset=+2]
1012

1113
== {product} 1.3.1
Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,2 @@
11
# CVE number, affected package, fixed in version(s), JIRA
2-
# none yet
3-
4-
# not yet fixed, built, or ready for release
5-
# NOTE: CVE is empty at the usual RH location so must manually edit generated .adoc file
6-
# to link to https://nvd.nist.gov/vuln/detail/CVE-2024-21538
7-
# once this is actually fixed in 1.3.z
8-
# CVE-2024-21538,cross-spawn,7.0.5,RHIDP-4864
2+
CVE-2024-21538,cross-spawn,7.0.5,RHIDP-4864
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
= {product} dependency updates
2+
3+
link:https://access.redhat.com/security/cve/CVE-2024-21538[CVE-2024-21538]::
4+
A Regular Expression Denial of Service (ReDoS) vulnerability was found in the cross-spawn package for Node.js. Due to improper input sanitization, an attacker can increase CPU usage and crash the program with a large, specially crafted string.

0 commit comments

Comments
 (0)