RHSA-2022:6187HighCVSS 7.5
Red Hat Security Advisory: Node Health Check Operator 0.3.1 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read
🎯 Affected products3
- Node Healthcheck Operator 0.3 for RHEL 8
- workload-availability/node-healthcheck-operator-bundle@sha256:8223bda16ac5ffac4b7407c849c4c30ee006ddafd34cad8a03d2af8314d56f58_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8
- workload-availability/node-healthcheck-rhel8-operator@sha256:3ce6b1557d00691dbaa869a1efe36098dc0b764196141d7777b82f355b35b8e3_amd64 as a component of Node Healthcheck Operator 0.3 for RHEL 8
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, see: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2022:6187
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107374
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6187.json