RHSA-2023:1042: Moderate: Custom Metrics Autoscaler Operator for Red Hat OpenShift (with security updates)
The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional<br>operator, based on the Kubernetes Event Driven Autoscaler (KEDA), that allows workloads to be scaled using additional metrics sources other than pod metrics.<br>This release builds upon updated compiler, runtime library, and base images for the purpose of resolving any potential security issues present in previous toolset versions.<br>This version makes use of newer tools and libraries to address the following issues:<br>golang: net/<a href="http:" target="blank">http:</a> improper sanitization of Transfer-Encoding header (CVE-2022-1705)<br>golang: go/parser: stack exhaustion in all Parse functions (CVE-2022-1962)<br>golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879)<br>golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)<br>golang: net/<a href="http:" target="blank">http:</a> handle server errors after sending GOAWAY (CVE-2022-27664)<br>golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)<br>golang: crypto/elliptic: panic caused by oversized scalar (CVE-2022-28327)<br>golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)<br>golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)<br>golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)<br>golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)<br>golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)<br>golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)<br>golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags (CVE-2022-32149)<br>golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)
Affected Software
Remediation
Event History
Frequently Asked Questions
What improvements are included in RHSA-2023:1042?
RHSA-2023:1042 includes updates to the Custom Metrics Autoscaler Operator, enhancing its compatibility and performance when scaling workloads based on various metrics.
How can I update to resolve issues addressed in RHSA-2023:1042?
You can update to the latest version of the Custom Metrics Autoscaler Operator within your Red Hat OpenShift environment to resolve issues specified in RHSA-2023:1042.
Is RHSA-2023:1042 applicable to all Red Hat OpenShift users?
RHSA-2023:1042 is specifically relevant to users of the Custom Metrics Autoscaler Operator in Red Hat OpenShift.
What is the impact if RHSA-2023:1042 is not addressed?
Failing to address RHSA-2023:1042 may lead to inefficient scaling of workloads, potentially impacting performance and resource utilization.
Where can I find more information about RHSA-2023:1042?
Details about RHSA-2023:1042, including the specific updates and fixes, can be found in the Red Hat advisory.