RHSA-2022:7399MediumCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.12.0 bug fix and security update

Published
January 17, 2023
Last Modified
June 4, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2022-32148 — golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-41316 — vault: insufficient certificate revocation list checking CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2023-0296 — openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher

🔗 References (951)