RHSA-2023:0727MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.12.3 security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2023-0056 — haproxy: segfault DoS
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:0727
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132867
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132872
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0727.json