RHSA-2023:0708: Moderate: Release of OpenShift Serverless Client kn 1.27.0
Red Hat OpenShift Serverless Client kn 1.27.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.27.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms.Security Fix(es): golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664) golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880) golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879)For more details about the security issue(s), including the impact; a CVSSscore; acknowledgments; and other related information refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0708?
The severity of RHSA-2023:0708 is categorized as important due to the potential impact on security features of the OpenShift Serverless Client.
How do I fix RHSA-2023:0708?
To fix RHSA-2023:0708, update the openshift-serverless-clients package to version 1.6.1-1.el8 or later.
What specific vulnerabilities are addressed in RHSA-2023:0708?
RHSA-2023:0708 addresses vulnerabilities related to the golang regexp/syntax package.
Which versions of OpenShift Serverless Client are affected by RHSA-2023:0708?
RHSA-2023:0708 affects versions of openshift-serverless-clients prior to 1.6.1-1.el8.
Is RHSA-2023:0708 relevant for non-Linux platforms?
Yes, RHSA-2023:0708 is relevant for both Linux and non-Linux platforms where the openshift-serverless-clients are utilized.