
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2024-1508 affects the Logging Subsystem for Red Hat OpenShift. It was disclosed on March 27, 2024, as part of a security update for Red Hat OpenShift logging components (Red Hat Advisory).
The vulnerability is rated as having a Moderate security impact according to Red Hat Product Security. The issue is related to the golang-protobuf component, specifically in the encoding/protojson and internal/encoding/json modules, which can result in an infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (Red Hat Advisory).
The vulnerability affects multiple versions of the Logging Subsystem for Red Hat OpenShift across different architectures including ARM 64, x86_64, IBM Power (little endian), and IBM Z and LinuxONE, all running on RHEL 8 (Red Hat Advisory).
Red Hat has released security updates to address this vulnerability. Users are advised to upgrade their OpenShift Container Platform 4.11 clusters and apply the errata update following the documentation. For Red Hat OpenShift Logging 5.7, specific upgrade instructions are provided in the OpenShift documentation (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."