Red Hat issued security updates across OpenShift Container Platform 4.13–4.16, Podman for RHEL 9, Red Hat Advanced Cluster Security 4.4.5, Cluster Observability Operator 0.4.1, and OpenShift Data Foundation 4.14 to remediate CVE-2024-6104. The flaw in go-retryablehttp can cause sensitive information contained in URLs to be written to log files, creating a risk of credential or token exposure to users and systems with log access. Affected OpenShift releases span RHEL 8 and RHEL 9 deployments on x86_64, aarch64, ppc64le, and s390x architectures.
Several advisories also fix related denial-of-service and input-validation flaws, including CVE-2024-37298 in gorilla/schema (memory exhaustion), CVE-2024-21538 in cross-spawn (regular-expression DoS), and defects in Go cryptography, protobuf JSON parsing, HAProxy, and other bundled components. Red Hat directs customers to update affected packages, container images, and clusters through supported release channels using the OpenShift web console or oc CLI, Red Hat package-update processes for Podman, and published image-update instructions for RHACS and Data Foundation.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:1866 for OpenShift Data Foundation 4.14 on RHEL 9. The updated images addressed CVE-2024-6104, CVE-2023-44270, CVE-2024-45337, and CVE-2024-45338.
Red Hat issued Moderate-severity RHSA-2024:11562 for OpenShift Container Platform 4.15.42. The updated packages and images remediated CVE-2024-6104 and included reliability fixes affecting networking, installation, upgrades, Prometheus, console, and IPsec deployments.
Red Hat published Low-severity RHSA-2024:11031, providing OpenShift Container Platform 4.14.43 container images. The release fixed CVE-2024-21538 in cross-spawn and included additional bug fixes and enhancements.
Red Hat issued Low-severity RHSA-2024:10839, releasing OpenShift Container Platform 4.15.40 images and package updates. The release fixed CVE-2024-21538, a regular-expression denial-of-service vulnerability in cross-spawn.
Red Hat published Moderate-rated RHSA-2024:8040 for Cluster Observability Operator 0.4.1. Updated images remediated CVE-2024-6104 and CVE-2024-24786, an invalid-JSON parsing issue that could cause an infinite loop in protojson.Unmarshal.
Red Hat issued Important-rated RHSA-2024:6194, providing Podman 4.9.4-10.el9_4 for RHEL 9. The update addressed CVE-2024-24783 in Go crypto/x509, CVE-2024-6104, and CVE-2024-37298.
Red Hat issued Important-rated RHSA-2024:6054 for Red Hat Advanced Cluster Security 4.4.5. The updated images fixed CVE-2024-37298, CVE-2024-3727, and CVE-2024-6104.
Red Hat issued Important-rated RHSA-2024:5634 for Podman on supported RHEL 9.2 update channels. Podman 4.4.1-20.el9_2 remediated CVE-2024-1394, CVE-2024-6104, and CVE-2024-37298.
Red Hat published RHSA-2024:4963, a Moderate-severity security update for OpenShift Container Platform 4.14.34. The RPM update remediated CVE-2024-37298 and CVE-2024-6104; Red Hat issued a separate advisory for the associated container images.
Red Hat issued RHSA-2024:4858, a Moderate-security update for OpenShift Container Platform 4.16.5. The updated packages and images addressed CVE-2024-37298 in gorilla/schema and CVE-2024-6104 in go-retryablehttp.
Red Hat issued RHSA-2024:4853, a Moderate-severity update for OpenShift Container Platform 4.15.24. It fixed CVE-2023-45539 in HAProxy, which could expose confidential data via untrimmed URI fragments, and CVE-2024-6104.
Red Hat released OpenShift Container Platform 4.13.46 packages and container images through RHSA-2024:4848 and RHSA-2024:4846. The release addressed CVE-2024-37298, CVE-2024-6104, and CVE-2023-29483, among other referenced vulnerabilities.
Red Hat issued RHSA-2024:4321, a Moderate-severity update for OpenShift Container Platform 4.15.21. The update remediated CVE-2024-6104 in go-retryablehttp, which could write sensitive URL information to log files, and included Kubernetes 1.28.11 and other bug fixes.
Red Hat released a Moderate-severity security update for OpenShift Container Platform 4.15.27. The updated container images fixed CVE-2024-6104 in go-retryablehttp and included other bug fixes and enhancements.
Red Hat released a Moderate-severity OpenShift Container Platform 4.16.26 security and bug-fix update. It remediated CVE-2024-6104 in go-retryablehttp and CVE-2024-21538 in cross-spawn.
Red Hat issued Important-rated RHSA-2024:7624 for OpenShift Data Foundation 4.14.11 on RHEL 9. Updated container images remediated CVE-2024-29041, CVE-2024-6104, CVE-2024-41818, and other vulnerabilities, upgraded Ceph to 6.1z8, and fixed a NooBaa operator startup issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.