RHSA-2022:1336: Important: OpenShift Container Platform 4.7.49 security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.See the following advisory for the container images for this release:https://access.redhat.com/errata/RHBA-2022:1337 Security Fix(es): haproxy: Denial of service via set-cookie2 header (CVE-2022-0711) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1336?
The severity of RHSA-2022:1336 is classified as important.
How do I fix RHSA-2022:1336?
To address RHSA-2022:1336, upgrade the affected haproxy packages to version 2.0.19-3.el8 or 2.0.19-3.el7 as applicable.
Which packages are affected by RHSA-2022:1336?
The affected packages include haproxy, haproxy-debugsource, haproxy20, and haproxy20-debuginfo.
Is there a fix for RHSA-2022:1336 for both el7 and el8?
Yes, fixes are available for both el7 and el8 versions of the affected packages.
What should I do if I cannot apply the update for RHSA-2022:1336 immediately?
If immediate updates cannot be applied, ensure that your system is monitored for any unusual activities until the patch is applied.