RHSA-2023:0918MediumCVSS 5.3
Red Hat Security Advisory: Service Binding Operator security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products6
- OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8
- ocp-tools-4/service-binding-operator-bundle@sha256:9ab3d5eb70c654270fef9e8e9d4e5b68e1ac3c86bd0e0dcd36cc6f8741be1603_amd64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8
- ocp-tools-4/service-binding-rhel8-operator@sha256:105fca817550739397c41b726262828bf79e478934a56049cf8c809ff370b58d_amd64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8
- ocp-tools-4/service-binding-rhel8-operator@sha256:d1934056d70be3cc6576002616ae617eed4574d72b1f7fcd914812c93dd31845_s390x as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8
- ocp-tools-4/service-binding-rhel8-operator@sha256:e4994674ce85b9551ddff28eb3da743f49085ead7ba34cbc9619c5f22eee1380_ppc64le as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8
- ocp-tools-4/service-binding-rhel8-operator@sha256:f1994579bb4b1395ea69486dec1b8c73f038ba6a5f787afff0cf42b48681c863_arm64 as a component of OpenShift Developer Tools and Services for OCP 4.9 for RHEL 8
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:0918
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/APPSVC-1204
- externalhttps://issues.redhat.com/browse/APPSVC-1256
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0918.json