{"schema_version":"1.9.0","id":"RHEA-2025:4438","published":"2026-08-08T10:06:24Z","modified":"2026-09-08T10:04:02Z","related":["GO-2024-3321","GO-2025-3553"],"upstream":["CVE-2024-45337","CVE-2025-30204"],"summary":"Red Hat Enhancement Advisory: Red Hat OpenShift Service on AWS 1.0 enhancements","affected":[{"package":{"name":"rosa","ecosystem":"Red Hat:openshift_service_on_aws:1::el8","purl":"pkg:rpm/redhat/rosa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.53-5be4e19.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHEA-2025:4438.json"}},{"package":{"name":"rosa-redistributable","ecosystem":"Red Hat:openshift_service_on_aws:1::el8","purl":"pkg:rpm/redhat/rosa-redistributable"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.53-5be4e19.el8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHEA-2025:4438.json"}}],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHEA-2025:4438"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-14567"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-14796"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-14846"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-14864"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-14892"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-14948"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-15159"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-4667"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OCM-9780"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/OSD-28968"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/ROSAENG-16904"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/ROSAENG-17384"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhea-2025_4438.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2024-45337"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2331720"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2024-45337"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45337"},{"type":"ARTICLE","url":"https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909"},{"type":"ARTICLE","url":"https://go.dev/cl/635315"},{"type":"ARTICLE","url":"https://go.dev/issue/70779"},{"type":"ARTICLE","url":"https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2024-3321"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-30204"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2354195"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-30204"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30204"},{"type":"ARTICLE","url":"https://github.com/golang-jwt/jwt/commit/0951d184286dece21f73c85673fd308786ffe9c3"},{"type":"ARTICLE","url":"https://github.com/golang-jwt/jwt/security/advisories/GHSA-mh63-6h87-95cp"},{"type":"ADVISORY","url":"https://pkg.go.dev/vuln/GO-2025-3553"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}