Red Hat's Multicluster Engine for Kubernetes 2.5.2 release images remediate two moderate-severity third-party vulnerabilities: CVE-2024-28176 in Jose and CVE-2024-21501 in sanitize-html. RHBA-2024:1775 supplies refreshed images for aarch64, ppc64le, s390x, and x86_64 deployments and also affects related Red Hat Advanced Cluster Management and OpenShift Container Platform components.
CVE-2024-28176 can cause excessive CPU or memory consumption during JWE decryption, creating a denial-of-service condition (CVSS 5.3). CVE-2024-21501 can allow an unauthenticated network attacker to enumerate server-side files and dependencies when sanitize-html permits the style attribute, exposing filesystem-layout information (CVSS 5.3); Red Hat Developer Hub remained listed as affected.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:3555 to fix affected console components in Multicluster Engine for Kubernetes 2.4 for RHEL 8 for CVE-2024-21501 and CVE-2024-28176.
Red Hat released RHSA-2024:1770, fixing the affected ose-monitoring-plugin-rhel8 component in Red Hat OpenShift Container Platform 4.15 for CVE-2024-21501.
Red Hat issued RHBA-2024:1793 to fix affected console components in Red Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9 for CVE-2024-21501 and CVE-2024-28176.
Red Hat published RHBA-2024:1775 for Multicluster Engine for Kubernetes 2.5.2 GA release images, addressing CVE-2024-21501 and CVE-2024-28176 with updated images for multiple architectures.
CVE-2024-28176, an uncontrolled resource-consumption flaw in Jose during JWE decryption, was publicly disclosed. The issue can cause excessive CPU or memory consumption and enable denial of service.
Red Hat issued RHBA-2025:1772 to fix CVE-2024-28176 in affected Red Hat Ceph Storage 7.1 components for RHEL 9, including ceph-nvmeof-cli, grafana, keepalived, and rhceph-7.
Red Hat issued RHBA-2024:3593, fixing the affected console-rhel8 component in Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 for CVE-2024-21501 and CVE-2024-28176.
A server-side use of sanitize-html with the style attribute permitted was identified as allowing unauthenticated attackers to enumerate files, including dependencies, and learn the target server's filesystem structure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.