First published: Tue Sep 08 2020(Updated: )
OpenShift Container Platform components are primarily written in Go (golang).<br>The golang.org/x/text contains text-related packages which are used for text operations, such as character encodings, text transformations, and locale-specific text handling.<br>Kibana is one of the major components of OpenShift Container Platform cluster logging.<br>It is a browser-based console interface to query, discover, and visualize the log data.<br>Security Fix(es):<br><li> kibana: XSS in TSVB visualization (ESA-2020-08) (CVE-2020-7015)</li> <li> golang.org/x/text: Possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:3578 is rated as moderate.
RHSA-2020:3578 affects components of the Red Hat OpenShift Container Platform that utilize golang.org/x/text.
To fix RHSA-2020:3578, you should update to the latest version of the affected Red Hat OpenShift Container Platform.
RHSA-2020:3578 impacts the Red Hat OpenShift Container Platform but does not specify exact versions.
There are no known workarounds for RHSA-2020:3578; it is recommended to apply the relevant updates.