Skip to content

Commit f93ee31

Browse files
authored
chore(release notes): add two more CVEs... (#699)
1 parent 362e043 commit f93ee31

File tree

2 files changed

+8
-4
lines changed

2 files changed

+8
-4
lines changed
Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,4 @@
11
# CVE number, affected package, fixed in version(s), JIRA
2+
CVE-2024-21536,http-proxy-middleware,2.0.7||3.0.3,RHIDP-4612
3+
CVE-2024-37890,ws,8.17.1||7.5.10||6.2.3||5.2.4,RHIDP-2733
24
CVE-2024-45590,body-parser,1.20.3,RHIDP-3917,mostly fixed but missed immobiliarelabs-backstage-plugin-gitlab-backend-dynamic
3-
4-
# not yet fixed, built, or ready for release
5-
# CVE-2024-37890,ws,8.17.1||7.5.10||6.2.3||5.2.4,RHIDP-2733
6-
# CVE-2024-21536,http-proxy-middleware,2.0.7||3.0.3,RHIDP-4612
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,10 @@
11
= {product} dependency updates
22

3+
link:https://access.redhat.com/security/cve/CVE-2024-21536[CVE-2024-21536]::
4+
A flaw was found in the http-proxy-middleware package. Affected versions of this package are vulnerable to denial of service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. This flaw allows an attacker to kill the Node.js process and crash the server by requesting certain paths.
5+
6+
link:https://access.redhat.com/security/cve/CVE-2024-37890[CVE-2024-37890]::
7+
A flaw was found in the Node.js WebSocket library (ws). A request with several headers exceeding the 'server.maxHeadersCount' threshold could be used to crash a ws server, leading to a denial of service.
8+
39
link:https://access.redhat.com/security/cve/CVE-2024-45590[CVE-2024-45590]::
410
A flaw was found in body-parser. This vulnerability causes denial of service via a specially crafted payload when the URL encoding is enabled.

0 commit comments

Comments
 (0)