First published: Mon Jan 11 2021(Updated: )
Red Hat OpenShift Serverless 1.9.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform version 4.5.<br>Security Fix(es):<br><li> golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586)</li> <li> golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Serverless | ||
Red Hat OpenShift Container Platform for IBM LinuxONE | >=4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:0072 is classified as moderate.
To fix RHSA-2021:0072, update the Red Hat OpenShift Serverless Operator to the latest available version that addresses the vulnerability.
RHSA-2021:0072 affects Red Hat OpenShift Serverless 1.9.0 running on Red Hat OpenShift Container Platform version 4.5.
RHSA-2021:0072 addresses a data race condition in the Golang library related to networking.
No specific workaround is provided for RHSA-2021:0072; applying the update is the recommended mitigation.