RHSA-2022:8626MediumCVSS 6.5
Red Hat Security Advisory: OpenShift Container Platform 4.11.17 packages and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-1705 — golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-32148 — golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2022:8626
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124669
- externalhttps://issues.redhat.com/browse/OCPBUGS-4045
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_8626.json