RHSA-2022:4863: Moderate: Release of OpenShift Serverless Version 1.22.1
Version 1.22.1 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10. This release includes security and bug fixes, and enhancements.Security Fixes in this release include: golang: crypto/elliptic IsOnCurve returns true for invalid field elements(CVE-2022-23806) golang: cmd/go: misinterpretation of branch names can lead to incorrect access control(CVE-2022-23773) golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString (CVE-2022-23772) For more details about the security issues, including the impact; a CVSS score; acknowledgments; and other related information refer to the CVE pages linked in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4863?
The severity is determined by the security vulnerabilities addressed in the release, which includes important security fixes.
How do I fix RHSA-2022:4863?
To fix RHSA-2022:4863, you should update your OpenShift Serverless Operator to version 1.22.1.
What versions of OpenShift are affected by RHSA-2022:4863?
RHSA-2022:4863 affects Red Hat OpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10.
What enhancements are included in RHSA-2022:4863?
RHSA-2022:4863 includes various bug fixes and performance enhancements alongside security improvements.
Is RHSA-2022:4863 a critical update?
RHSA-2022:4863 contains security fixes that are significant, but the criticality depends on your specific deployment and risk assessment.