CVE-2024-4437 - CVE House
Back to Database
Status published High CVE-2024-4437

Etcd: incomplete fix for cve-2021-44716 in openstack platform

Vulnerability Description

The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-4437

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat OpenStack Platform 16.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0
Vulnerable Versions:
3.3.23, 0:3.3.23-16.el8ost

Timeline

Official Publish: May 8th, 2024
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)