RHSA-2022:7407: Moderate: Service Binding Operator 1.3.1 security update
Service Binding Operator 1.3.1 is now available for OpenShift Developer Tools and Services for OCP 4.9 +Security Fix(es): golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags (CVE-2022-32149) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:7407?
The severity of RHSA-2022:7407 is classified as moderate.
What vulnerability does RHSA-2022:7407 address?
RHSA-2022:7407 addresses a performance issue in golang.org/x/text/language related to CVE-2022-32149.
How do I fix RHSA-2022:7407?
To fix RHSA-2022:7407, update your OpenShift Developer Tools and Services to version 1.3.1 or later.
Which versions of OpenShift are affected by RHSA-2022:7407?
RHSA-2022:7407 affects OpenShift Container Platform 4.9 and newer versions.
Is there a workaround for the vulnerability in RHSA-2022:7407?
There are no specific workarounds recommended for the issue identified in RHSA-2022:7407.