First published: Wed Nov 18 2020(Updated: )
Red Hat OpenShift Serverless 1.11.0 is a generally available release of the<br>OpenShift Serverless Operator. This version of the OpenShift Serverless<br>Operator is supported on Red Hat OpenShift Container Platform version 4.6.<br>Security Fix(es): <br><li> golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, and other related information, see the CVE page(s) listed in the<br>References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:5149 is considered moderate due to the security vulnerabilities identified in the OpenShift Serverless Operator.
To fix RHSA-2020:5149, update your Red Hat OpenShift Serverless Operator to version 1.11.1 or later.
RHSA-2020:5149 affects the Red Hat OpenShift Serverless Operator 1.11.0 on Red Hat OpenShift Container Platform version 4.6.
No, RHSA-2020:5149 is classified as moderate rather than critical, but it is still important to address the identified issues.
RHSA-2020:5149 addresses potential vulnerabilities in the golang.org/x/text library, among other components.