First published: Wed May 11 2022(Updated: )
Release osp-director-operator images<br>Security Fix(es):<br><li> golang: kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote (CVE-2019-11253)</li> <li> golang: golang-github-miekg-dns: predictable TXID can lead to response forgeries (CVE-2019-19794)</li> <li> golang: containerd: unrestricted access to abstract Unix domain socket can lead to privileges (CVE-2020-15257)</li> <li> golang: ulikunitz/xz: Infinite loop in readUvarint allows for denial of service (CVE-2021-29482)</li> <li> golang: containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.