Red Hat released Important security updates for OpenShift Service Mesh Containers 2.5.5 and 2.6.2 and OpenShift Serverless Logic 1.34.0, remediating flaws in bundled Node.js and infrastructure components. The updates address CVE-2024-43799 in the send library, where untrusted input passed to SendStream.redirect() can result in untrusted code execution, and CVE-2024-43788 in Webpack's AutoPublicPathRuntimeModule, a DOM-clobbering flaw that can enable XSS when attackers can inject insufficiently sanitized scriptless HTML elements with name or id attributes.
The Service Mesh advisories also fix issues in serve-static, Express, body-parser, Envoy, path-to-regexp, and libcurl, including denial-of-service conditions, unsafe redirects, regular-expression DoS, log injection, externally manipulable x-envoy headers, Envoy crashes, and a libcurl ASN.1 date-parser overread. The Serverless Logic update additionally addresses axios SSRF and input-sanitization issues and an unbounded Vert.x gRPC message-size condition. Affected deployments span RHEL 8 on x86_64, ARM64/aarch64, ppc64le, and s390x where applicable; Red Hat recommends applying relevant prior errata before deploying the updates.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:8023, releasing OpenShift Serverless Logic 1.34.0 for affected RHEL 8 architectures. The update addressed CVE-2024-43799 and CVE-2024-43788 as well as axios, Express, Vert.x gRPC, and serve-static vulnerabilities.
Red Hat issued Moderate advisory RHSA-2024:7706 for the Red Hat build of Cryostat 3 on RHEL 8. The update fixes webpack DOM-clobbering flaw CVE-2024-43788 and DOMPurify prototype-pollution XSS vulnerability CVE-2024-45801.
Red Hat issued Important advisory RHSA-2024:7724 for OpenShift Service Mesh Containers 2.4.11. The update remediated Envoy, webpack, send, and serve-static flaws, including CVE-2024-43788, CVE-2024-43799, CVE-2024-32475, CVE-2024-32976, and CVE-2024-43800.
Red Hat issued Important advisory RHSA-2024:7726 for OpenShift Service Mesh Containers 2.6.2. The update remediated the send code-execution flaw, webpack DOM-clobbering flaw, and additional issues affecting serve-static, Express, path-to-regexp, body-parser, Envoy, and libcurl.
Red Hat issued Important advisory RHSA-2024:7725 for OpenShift Service Mesh Containers 2.5.5, addressing CVE-2024-43799 and CVE-2024-43788 along with vulnerabilities in serve-static, Envoy, and body-parser.
Red Hat issued advisories addressing DOMPurify prototype-pollution XSS vulnerability CVE-2024-45801 in Network Observability, Ansible Automation Platform, OpenShift Dev Spaces, and OpenShift Container Platform. The flaw can let specially nested malicious HTML bypass DOMPurify depth checks, and is fixed upstream in versions 2.5.4 and 3.1.3.
Red Hat issued advisories remediating CVE-2024-43800 in Network Observability, OpenShift Data Foundation, Migration Toolkit for Containers, HawtIO, and OpenShift Container Platform. The fixes address serve-static passing sanitized but untrusted input to redirect(), which could allow execution of untrusted code.
Webpack fixed CVE-2024-43788, a DOM-clobbering issue in AutoPublicPathRuntimeModule, in version 5.94.0. The gadget had been observed enabling XSS in Canvas LMS when attacker-controlled scriptless HTML was insufficiently sanitized.
The Node.js send library patched CVE-2024-43799 in version 0.19.0. The flaw involved untrusted input being passed to SendStream.redirect(), potentially enabling execution of untrusted code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.