First published: Mon May 09 2022(Updated: )
Version 1.22.0 of the OpenShift Serverless Operator is supported on Red Hat<br>OpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10. This release includes security and bug fixes and enhancements. <br>For more information, see the documentation linked in the Solution section.<br>Security Fixes in this release include:<br><li> golang: archive/zip: Reader.Open panics on empty string (CVE-2021-41772)</li> <li> golang: debug/macho: invalid dynamic symbol table command can cause panic (CVE-2021-41771)</li> For more details about the security issues, including the impact, a CVSS<br>score, acknowledgments, and other related information refer to the CVE pages<br>linked in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE | >=4.6<4.11 | |
Red Hat OpenShift Serverless Operator | =1.22.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1747 is classified as low.
To fix RHSA-2022:1747, update to version 1.22.1 or later of the OpenShift Serverless Operator.
RHSA-2022:1747 affects Red Hat OpenShift Serverless Operator version 1.22.0 on OpenShift Container Platform versions 4.6 to 4.10.
RHSA-2022:1747 was released as part of a series of updates for OpenShift on a specified date in 2022.
RHSA-2022:1747 includes security fixes, bug fixes, and enhancements to the OpenShift Serverless Operator.