First published: Wed May 19 2021(Updated: )
Red Hat OpenShift Serverless 1.10.2 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform version 4.5.<br>Security Fix(es):<br><li> golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114)</li> <li> golang: cmd/go: packages using cgo can cause arbitrary code execution at build time (CVE-2021-3115)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Serverless | ||
Red Hat OpenShift Container Platform for IBM LinuxONE | >=4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:2021 is classified as moderate.
To fix RHSA-2021:2021, update to the latest version of the OpenShift Serverless Operator supported on Red Hat OpenShift Container Platform version 4.5.
RHSA-2021:2021 affects Red Hat OpenShift Serverless 1.10.2.
The purpose of RHSA-2021:2021 is to address security vulnerabilities in the OpenShift Serverless Operator.
Yes, RHSA-2021:2021 addresses security issues related to the crypto/elliptic package in golang.