Red Hat Security Advisory: Release of OpenShift Serverless 1.29.1
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-24539 — golang: html/template: improper sanitization of CSS values CVE-2023-29400 — golang: html/template: improper handling of empty HTML attributes
🎯 Affected products107
- Red Hat OpenShift Serverless 1.29
- openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:330fadd0c42aa5686afa305adbbb1aaff7adc6c034895c04b354c7202f70ae7f_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:549af9316f70dde2ae271e4d2de13098a339bc3dd08e4c432c60c0091cbb4cac_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:f6e76d2bdc56aa9fe61651bc060eb439814ed39de8bfaeb553a08d214911bec2_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/client-kn-rhel8@sha256:30f60c00e71f593d9ab4968dbb08b6f7be873913dbd7880829025bfc05e14412_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/client-kn-rhel8@sha256:416962200f7e9c40412734a7ba5bd533523b3b8c4d8bdbe125c2ef037449f5ec_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/client-kn-rhel8@sha256:8f9ba47649bda71f0f4461efb553f9b1bad447f34b1ce4dc90a7ae4d1dccf5bc_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:75156597dbfcfd4b34c6e8eabfe4b634b33d392ec008337b03d529e4210e0460_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:d49558ccceed79886b129d0e3d899ad7942ae2f5ca6d7851bf9ebb2a5aef43f8_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:fb5ffb2100281bdbc63102417efdd28f76c327b07c3dbb96bf81e3d2fcca6c8a_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-controller-rhel8@sha256:0f3e364f84cfd32e317990093be17421b31968c44f10521eab5e20f76c6eee9b_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-controller-rhel8@sha256:62955898ee5138e7f5fdda71cc962d12dc98d02a99cce04703c411fe0800ce6d_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-controller-rhel8@sha256:d664f01c46bec5d6fb4479e130acf527cec175b57128c8279b56359cb634c7fc_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:20a17e414ef48c0bc7e24c5d415b7f386638c72112bb9a991cb2051a677115b5_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:331ca39e8ecfc315ce6bffc9e57a1ee513fad81fbc792e9b2f5ab6722bbad27d_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:d644d8ece94c938087609462a40a2a02e340ecbee1dd622198df9e2088b91302_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:9787e104273dc984da252672462f1299cd5b8684e5bbc260149ccfc89ac2a906_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:9873d3c295309ac9ba52469a6597a1d2db7c833974d78fba9999586470cd132f_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:bf348f140ed66e26638b2faa83ef76873e0440832615bf61a13f104e029d6304_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-controller-rhel8@sha256:03e1d4db4a417eb3dfd6aab53ec82e1a3a61b71ab1de29564783c04505b8af7c_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-controller-rhel8@sha256:845a227e506a34ffb10e629ba4bec674f3869f6d8e1d6c1dd7708478cb32fa99_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-controller-rhel8@sha256:c1769c408ae773f0b226fcf6b294f0a56969a8e1cbae647bca14f11f390055bd_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8@sha256:06c446d4067d12cfdbb779ff38d0fdcc1394cf4445131c82de7f9b2632695e31_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8@sha256:2f8521f18acd7bf75486bf88c99e436085858c878b7f85d9881d510a487d909b_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8@sha256:d94d5823e18a56ca067d7e5b715c3c413ef3362be4f3bb78acc8a84c1d6f630a_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-post-install-rhel8@sha256:066839cb9458d59ebdcdf37a66d9b793c65c4db04300ba4d9de159fa98ef9591_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-post-install-rhel8@sha256:2aa958fa305e2558e0fd9208db9e3e7c894b42ed500ffbb352fd37da60d23630_amd64 as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-post-install-rhel8@sha256:d1ab34315ed3e771ddc4239d83f5307e21bc53c66a520d2bb40ffd0d327f9b2e_ppc64le as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-receiver-rhel8@sha256:8c577c57ef75af592a9489e83a10437c787b24e203aed3a44974ab307d4b7179_s390x as a component of Red Hat OpenShift Serverless 1.29
- openshift-serverless-1/eventing-kafka-broker-receiver-rhel8@sha256:a23c471b9a8ea80549ecc3d0ab87b09c3debffcd578bb4120fe97802b399500c_amd64 as a component of Red Hat OpenShift Serverless 1.29
- +77 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2023:4472
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://access.redhat.com/documentation/en-us/openshift_container_platform/4.10/html/serverless/index
- externalhttps://access.redhat.com/documentation/en-us/openshift_container_platform/4.11/html/serverless/index
- externalhttps://access.redhat.com/documentation/en-us/openshift_container_platform/4.12/html/serverless/index
- externalhttps://access.redhat.com/documentation/en-us/openshift_container_platform/4.13/html/serverless/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4472.json