First published: Tue Sep 06 2022(Updated: )
Gatekeeper Operator v0.2<br>Gatekeeper is an open source project that applies the OPA Constraint<br>Framework to enforce policies on your Kubernetes clusters. <br>This advisory contains the container images for Gatekeeper that include bug<br>fixes and container upgrades. <br>Note: Gatekeeper support from the Red Hat support team is limited to where it is integrated and used with Red Hat Advanced Cluster Management<br>for Kubernetes. For support options for any other use, see the Gatekeeper<br>open source project website at:<br><a href="https://open-policy-agent.github.io/gatekeeper/website/docs/howto/." target="_blank">https://open-policy-agent.github.io/gatekeeper/website/docs/howto/.</a> Security fix:<br><li> CVE-2022-30629: gatekeeper-container: golang: crypto/tls: session tickets lack random ticket_age_add</li> <li> CVE-2022-1705: golang: net/<a href="http:" target="_blank">http:</a> improper sanitization of Transfer-Encoding header</li> <li> CVE-2022-1962: golang: go/parser: stack exhaustion in all Parse* functions</li> <li> CVE-2022-28131: golang: encoding/xml: stack exhaustion in Decoder.Skip</li> <li> CVE-2022-30630: golang: io/fs: stack exhaustion in Glob</li> <li> CVE-2022-30631: golang: compress/gzip: stack exhaustion in Reader.Read</li> <li> CVE-2022-30632: golang: path/filepath: stack exhaustion in Glob</li> <li> CVE-2022-30635: golang: encoding/gob: stack exhaustion in Decoder.Decode</li> <li> CVE-2022-30633 golang: encoding/xml: stack exhaustion in Unmarshal</li> <li> CVE-2022-32148 golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working</li>
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.