—
GO-2024-2789
Cluster Monitoring Operator contains a credentials leak in github.com/openshift/cluster-monitoring-operator
Details
Cluster Monitoring Operator contains a credentials leak in github.com/openshift/cluster-monitoring-operator
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/openshift/cluster-monitoring-operator
Introduced in:
0No fixed version published yet for github.com/openshift/cluster-monitoring-operator (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/advisories/GHSA-x5m7-63c6-fx79[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-1139[ADVISORY]
- https://github.com/openshift/cluster-monitoring-operator/commit/1cfbe9ffafe1e43f8f87a451b72fddf5d76fa4e3[FIX]
- https://github.com/openshift/cluster-monitoring-operator/pull/1747[FIX]
- https://access.redhat.com/errata/RHSA-2024:1887[WEB]
- https://access.redhat.com/errata/RHSA-2024:1891[WEB]
- https://access.redhat.com/errata/RHSA-2024:2047[WEB]
- https://access.redhat.com/errata/RHSA-2024:2782[WEB]
- https://access.redhat.com/security/cve/CVE-2024-1139[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2262158[WEB]
- https://github.com/openshift/cluster-monitoring-operator/blob/d45a3335c2bbada0948adef9fcba55c4e14fa1d7/pkg/manifests/manifests.go#L3135[WEB]