CVE-2024-4438
Etcd: incomplete fix for cve-2023-39325/cve-2023-44487 in openstack platform
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.
El paquete etcd distribuido con la plataforma Red Hat OpenStack tiene una soluciĆ³n incompleta para CVE-2023-39325/CVE-2023-44487, conocida como Rapid Reset. Este problema ocurre porque el paquete etcd en la plataforma Red Hat OpenStack usa http://golang.org/x/net/http2 en lugar del proporcionado por las versiones de Red Hat Enterprise Linux, lo que significa que debe actualizarse en el momento de la compilaciĆ³n.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-05-02 CVE Reserved
- 2024-05-08 CVE Published
- 2024-11-24 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2024:2729 | 2024-05-30 | |
https://access.redhat.com/errata/RHSA-2024:3352 | 2024-05-30 | |
https://access.redhat.com/errata/RHSA-2024:3467 | 2024-05-30 | |
https://access.redhat.com/security/cve/CVE-2024-4438 | 2024-05-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2279365 | 2024-05-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | * | - |
Affected
|