• Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.0.beta
    • CentOS Stream 10, rhel-10.0.beta
    • php
    • None
    • None
    • Rebase
    • rhel-sst-cs-stacks
    • ssg_core_services
    • 22
    • 2
    • False
    • Hide

      None

      Show
      None
    • None
    • Red Hat Enterprise Linux
    • None
    • None

      Rebase to 8.3.7

      So fix low CVEs

      • CVE-2024-2756 _Host-/_Secure- cookie bypass due to partial CVE-2022-31629 fix
      • CVE-2024-3096 password_verify can erroneously return true,
        opening ATO risk
      • CVE-2024-2757 mb_encode_mimeheader runs endlessly for some inputs

      And add backport for ARGON2 support from OpenSSL 3.2 (from 8.4)

              rcollet@redhat.com Remi Collet
              rcollet@redhat.com Remi Collet
              Remi Collet Remi Collet
              Iveta Cesalova Iveta Cesalova
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: