RHSA-2022:5673: Important: Release of containers for OSP 16.2.z director operator tech preview
Release osp-director-operator imagesSecurity Fix(es): go-getter: unsafe download (issue 1 of 3) [Important] (CVE-2022-30321) go-getter: unsafe download (issue 2 of 3) [Important] (CVE-2022-30322) go-getter: unsafe download (issue 3 of 3) [Important] (CVE-2022-30323) go-getter: command injection vulnerability [Important] (CVE-2022-26945) golang.org/x/crypto: empty plaintext packet causes panic [Moderate] (CVE-2021-43565) containerd: insufficiently restricted permissions on container root and plugin directories [Moderate] (CVE-2021-41103)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5673?
The severity of RHSA-2022:5673 is classified as Important.
What vulnerabilities are addressed in RHSA-2022:5673?
RHSA-2022:5673 addresses three vulnerabilities related to unsafe downloads of the go-getter library.
How do I fix RHSA-2022:5673?
To fix RHSA-2022:5673, update the affected packages to the latest version provided in the security advisory.
What are the CVE identifiers associated with RHSA-2022:5673?
The CVE identifiers associated with RHSA-2022:5673 are CVE-2022-30321, CVE-2022-30322, and others.
Is there a workaround for RHSA-2022:5673?
There are currently no documented workarounds for the vulnerabilities in RHSA-2022:5673.