Red Hat Security Advisory: OpenShift Container Platform 4.12.0 packages and security update
🔗 CVE IDs covered (16)
📋 Description
CVE-2021-4235 — go-yaml: Denial of Service in go-yaml CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-2995 — cri-o: incorrect handling of the supplementary groups CVE-2022-2996 — python-scciclient: missing server certificate verification CVE-2022-3162 — kubernetes: Unauthorized read of Custom Resources CVE-2022-3172 — kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF) CVE-2022-3259 — OpenShift: Missing HTTP Strict Transport Security CVE-2022-3466 — cri-o: Security regression of CVE-2022-27652 CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-32148 — golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2022:7398
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2103220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2121632
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2127804
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156727
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2022_7398.json