Red Hat released OpenShift Container Platform 4.15.37 through advisory RHSA-2024:8425, rated Important, updating platform container images for OCP 4.15 deployments. The update remediates nine disclosed vulnerabilities in Go and related ecosystem components, including a go-git path-traversal flaw that can lead to remote code execution, alongside multiple denial-of-service issues.
Organizations operating affected OpenShift 4.15 clusters on RHEL 8 or RHEL 9 should upgrade through their applicable OpenShift release channel using the web console or OpenShift CLI. The release applies across x86_64, s390x, ppc64le, and aarch64 architectures and also includes non-security bug fixes and architecture-specific release-image digests.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated advisory RHSA-2024:8425, releasing OpenShift Container Platform 4.15.37 container images for RHEL 8 and RHEL 9. The update remediated nine vulnerabilities in Go and related components, including go-git path traversal/RCE and several denial-of-service issues, and included non-security fixes.
Red Hat issued Critical advisory RHSA-2024:6221 for the general-availability release of OpenShift Builds 1.1.0. The RHEL 9-based Builds Operator release integrated the CSI driver and remediated seven flaws, including go-git path traversal/RCE (CVE-2023-49569) and Go HTTP/2 CONTINUATION-frame denial of service (CVE-2023-45288).
Red Hat issued Important advisory RHSA-2024:2047 for OpenShift Container Platform 4.13.41 on RHEL 8 and RHEL 9 across supported architectures. The update remediated go-git flaws CVE-2023-49569 and CVE-2023-49568, plus CVE-2024-1139 in cluster-monitoring-operator, CVE-2024-1725 in kubevirt-csi, and CVE-2021-4294 in osin.
Red Hat recorded CVE-2023-45290 after Go's multipart form parser was found to allow extremely long individual form lines to consume arbitrary memory. The flaw is reachable through Request.ParseMultipartForm and indirectly through FormValue, PostFormValue, and FormFile; Go corrected ParseMultipartForm to impose form-line size limits.
Red Hat reported Bug 2268273 for CVE-2023-45288, a high-severity denial-of-service flaw in Go's net/http and golang.org/x/net/http2 packages. Unbounded HTTP/2 CONTINUATION frames can let an attacker submit excessive headers, causing CPU consumption while they are read, decoded, and discarded.
Red Hat issued RHSA-2024:0989 to fix CVE-2023-49569 in multicluster-globalhub-grafana-rhel8 for multicluster-globalhub 1.0 on RHEL 8.
Red Hat issued Critical advisory RHSA-2024:0845, making OpenShift Container Platform 4.13.34 available for supported RHEL 8 and RHEL 9 architectures. The update remediated go-git path traversal/RCE vulnerability CVE-2023-49569 and go-git denial-of-service vulnerability CVE-2023-49568.
Red Hat issued Critical advisory RHSA-2024:0740 for OpenShift Container Platform 4.13.33 on RHEL 8 and RHEL 9 across x86_64, aarch64, ppc64le, and s390x architectures. The update remediated go-git path traversal/possible remote-code-execution flaw CVE-2023-49569 and go-git denial-of-service flaw CVE-2023-49568.
Red Hat issued Critical advisory RHSA-2024:0820 for Red Hat Advanced Cluster Management for Kubernetes 2.8.5 General Availability container images on RHEL 8 x86_64. The update remediated go-git denial-of-service flaw CVE-2023-49568 and path traversal/possible remote-code-execution flaw CVE-2023-49569, along with other vulnerabilities and product defects.
Red Hat issued Critical advisory RHSA-2024:0735, releasing OpenShift Container Platform 4.14.12 container images and packages for supported RHEL 8 and RHEL 9 architectures. The update remediated go-git flaws CVE-2023-49569 and CVE-2023-49568, graphql-go stack-overflow denial of service CVE-2022-21708, and additional vulnerabilities.
Red Hat issued Critical advisory RHSA-2024:0692 for OpenShift GitOps 1.10.2 on x86_64, ppc64le, s390x, and aarch64. The update remediated Argo CD cross-server request forgery flaw CVE-2024-22424 and go-git vulnerabilities CVE-2023-49569 and CVE-2023-49568.
Red Hat opened Bug 2258143 for CVE-2023-49569, a flaw in go-git versions before 5.11 where malicious Git server replies can write outside the intended repository path and potentially enable remote code execution. The issue affects use of go-billy's ChrootOS backend, including go-git's default Plain Open and Clone operations, but not BoundOS or in-memory filesystems.
Red Hat tracked CVE-2024-24791, in which Go's net/http HTTP/1.1 client can leave reused connections invalid after handling an Expect: 100-continue request that receives a non-informational response. The flaw can cause denial of service in net/http/httputil.ReverseProxy deployments, and Red Hat issued fixes across RHEL, OpenShift, and other products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcedocs.openshift.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.