Uploaded image for project: 'Data Foundation Bugs'
  1. Data Foundation Bugs
  2. DFBUGS-922

CVE-2024-45296 odf-console-container: Backtracking regular expressions cause ReDoS [openshift-data-foundation-4.15.z]

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • odf-4.15.9
    • odf-4.15.z
    • management-console
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • Committed
    • ?
    • ?
    • 4.15.9-1
    • Committed
    • None

      Verification: check in the container image build logs that the fixed
      version for "path-to-regexp" are downloaded/used:
      │ └─┬ react-router@5.3.4
      │ └── path-to-regexp@1.9.0 <=== fixed version

            [DFBUGS-922] CVE-2024-45296 odf-console-container: Backtracking regular expressions cause ReDoS [openshift-data-foundation-4.15.z]

            Alfonso Martínez Hidalgo created issue -
            Data Foundation bot made changes -
            Fix Version/s New: odf-4.18 [ 12430921 ]
            Alfonso Martínez Hidalgo made changes -
            Assignee Original: Anjana Sriram [ asriram@redhat.com ] New: Alfonso Martínez Hidalgo [ almartin-storage-ocs ]
            OpenShift Prow Bot made changes -
            Status Original: New [ 10016 ] New: POST [ 15726 ]
            OpenShift Prow Bot made changes -
            Remote Link New: This issue links to "red-hat-storage/odf-console#1708: DFBUGS-922: [release-4.15] Fix security issue: Backtracking regular expressions (Web Link)" [ 1861030 ]
            DPTP Bot made changes -
            Remote Link New: This issue links to "red-hat-storage/odf-console#1709: DFBUGS-922: [release-4.15-compatibility] Fix security issue: Backtracking regular expressions (Web Link)" [ 1860894 ]
            Alfonso Martínez Hidalgo made changes -
            Dev Approval Original: ? [ 17170 ] New: Committed [ 15271 ]
            Alfonso Martínez Hidalgo made changes -
            Target Release Original: odf-4.18 [ 12430921 ] New: odf-4.15.8 [ 12435464 ]
            Alfonso Martínez Hidalgo made changes -
            Fix Version/s New: odf-4.15.z [ 12435505 ]
            Fix Version/s Original: odf-4.18 [ 12430921 ]
            Data Foundation bot made changes -
            Dev Approval Original: Committed [ 15271 ] New: ? [ 17170 ]
            Alfonso Martínez Hidalgo made changes -
            Component/s New: management-console [ 12402188 ]
            Affects Version/s New: odf-4.15.z [ 12435505 ]
            Data Foundation bot made changes -
            Assignee Original: Alfonso Martínez Hidalgo [ almartin-storage-ocs ] New: Nishanth Thomas [ rhn-engineering-nthomas ]
            Alfonso Martínez Hidalgo made changes -
            Assignee Original: Nishanth Thomas [ rhn-engineering-nthomas ] New: Alfonso Martínez Hidalgo [ almartin-storage-ocs ]
            Alfonso Martínez Hidalgo made changes -
            Link New: This issue is cloned by DFBUGS-923 [ DFBUGS-923 ]
            Alfonso Martínez Hidalgo made changes -
            Target Release Original: odf-4.15.8 [ 12435464 ]
            Alfonso Martínez Hidalgo made changes -
            Dev Approval Original: ? [ 17170 ] New: Committed [ 15271 ]
            Eran Tamir made changes -
            Target Release New: odf-4.15.z [ 12435505 ]
            Eran Tamir made changes -
            Fix Version/s Original: odf-4.15.z [ 12435505 ]
            Nishanth Thomas made changes -
            Target Release Original: odf-4.15.z [ 12435505 ] New: odf-4.15.9 [ 12435530 ]
            Data Foundation bot made changes -
            Dev Approval Original: Committed [ 15271 ] New: ? [ 17170 ]
            Krishnaram Karthick Ramdoss made changes -
            QE Approval Original: ? [ 17171 ] New: Committed [ 15292 ]
            Gowtham Shanmugasundaram made changes -
            Dev Approval Original: ? [ 17170 ] New: Committed [ 15271 ]
            Data Foundation bot made changes -
            Fix Version/s New: odf-4.15.9 [ 12435530 ]
            Target Version New: odf-4.15.9 [ 12435530 ]
            Data Foundation bot made changes -
            Need Info From New: Alfonso Martínez Hidalgo [ almartin ]
            Alfonso Martínez Hidalgo made changes -
            Need Info From Original: Alfonso Martínez Hidalgo [ almartin ]
            OpenShift Prow Bot made changes -
            Status Original: POST [ 15726 ] New: MODIFIED [ 14454 ]
            Sanjal Katiyar made changes -
            Status Original: MODIFIED [ 14454 ] New: POST [ 15726 ]
            OpenShift Prow Bot made changes -
            Status Original: POST [ 15726 ] New: MODIFIED [ 14454 ]
            DPTP Bot made changes -
            Remote Link New: This issue links to "red-hat-storage/odf-console#1777: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884804 ]
            DPTP Bot made changes -
            Remote Link New: This issue links to "red-hat-storage/odf-console#1778: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ]
            DPTP Bot made changes -
            Remote Link Original: This issue links to "red-hat-storage/odf-console#1778: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ] New: This issue links to "red-hat-storage/odf-console#1778: [release-4.15-compatibility] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ]
            Gowtham Shanmugasundaram made changes -
            Status Original: MODIFIED [ 14454 ] New: POST [ 15726 ]
            DPTP Bot made changes -
            Remote Link Original: This issue links to "red-hat-storage/odf-console#1777: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884804 ] New: This issue links to "red-hat-storage/odf-console#1777: Bug DFBUGS-922: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884804 ]
            DPTP Bot made changes -
            Remote Link Original: This issue links to "red-hat-storage/odf-console#1778: [release-4.15-compatibility] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ] New: This issue links to "red-hat-storage/odf-console#1778: Bug DFBUGS-922: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ]
            DPTP Bot made changes -
            Remote Link Original: This issue links to "red-hat-storage/odf-console#1778: Bug DFBUGS-922: [release-4.15] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ] New: This issue links to "red-hat-storage/odf-console#1778: Bug DFBUGS-922: [release-4.15-compatibility] Reverting back CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1884805 ]
            OpenShift Prow Bot made changes -
            Status Original: POST [ 15726 ] New: MODIFIED [ 14454 ]
            DPTP Bot made changes -
            Remote Link New: This issue links to "red-hat-storage/odf-console#1798: DFBUGS-922: [release-4.15] Revert: Reverting CVE fix for DFBUGS-922 and DFBUGS-934 (Web Link)" [ 1888615 ]
            Alfonso Martínez Hidalgo made changes -
            Status Original: MODIFIED [ 14454 ] New: POST [ 15726 ]
            DPTP Bot made changes -
            Remote Link New: This issue links to "red-hat-storage/odf-console#1799: DFBUGS-922: [release-4.15-compatibility] Revert: Reverting fix for DFBUGS-922 … (Web Link)" [ 1888664 ]
            OpenShift Prow Bot made changes -
            Status Original: POST [ 15726 ] New: MODIFIED [ 14454 ]
            Gowtham Shanmugasundaram made changes -
            Link New: This issue is depended on by DFBUGS-69 [ DFBUGS-69 ]
            Gowtham Shanmugasundaram made changes -
            Link New: This issue is depended on by DFBUGS-259 [ DFBUGS-259 ]
            Gowtham Shanmugasundaram made changes -
            Link New: This issue is depended on by DFBUGS-212 [ DFBUGS-212 ]
            Gowtham Shanmugasundaram made changes -
            Link New: This issue is depended on by DFBUGS-677 [ DFBUGS-677 ]
            Gowtham Shanmugasundaram made changes -
            Link New: This issue is depended on by DFBUGS-255 [ DFBUGS-255 ]
            Boris Ranto made changes -
            Status Original: MODIFIED [ 14454 ] New: ON_QA [ 15723 ]
            Boris Ranto made changes -
            Prod build version New: 4.15.9-1
            Errata Tool made changes -
            Remote Link New: This issue links to "RHBA-2024:144276 (Web Link)" [ 1892025 ]
            Shivam Durgbuns made changes -
            Status Original: ON_QA [ 15723 ] New: Verified [ 10015 ]
            Errata Tool made changes -
            Resolution New: Done-Errata [ 10803 ]
            Status Original: Verified [ 10015 ] New: Closed [ 6 ]

              almartin-storage-ocs Alfonso Martínez Hidalgo
              almartin-storage-ocs Alfonso Martínez Hidalgo
              Votes:
              0 Vote for this issue
              Watchers:
              14 Start watching this issue

                Created:
                Updated:
                Resolved: