First published: Tue Jan 17 2023(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>This advisory contains the container images for Red Hat OpenShift Container Platform 4.12.0. See the following advisory for the RPM packages for this release:<br><a href="https://access.redhat.com/errata/RHSA-2022:7398" target="_blank">https://access.redhat.com/errata/RHSA-2022:7398</a> Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes:<br><a href="https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html" target="_blank">https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html</a> Security Fix(es):<br><li> golang: out-of-bounds read in golang.org/x/text/language leads to DoS</li> (CVE-2021-38561)<br><li> golang: net/<a href="http:" target="_blank">http:</a> improper sanitization of Transfer-Encoding header</li> (CVE-2022-1705)<br><li> golang: archive/tar: unbounded memory consumption when reading headers</li> (CVE-2022-2879)<br><li> golang: net/http/httputil: ReverseProxy should not forward unparseable</li> query parameters (CVE-2022-2880)<br><li> prometheus/client_golang: Denial of service using</li> InstrumentHandlerCounter (CVE-2022-21698)<br><li> golang: net/http/httputil: NewSingleHostReverseProxy - omit</li> X-Forwarded-For not working (CVE-2022-32148)<br><li> golang: net/url: JoinPath does not strip relative path components in all</li> circumstances (CVE-2022-32190)<br><li> vault: insufficient certificate revocation list checking (CVE-2022-41316)</li> <li> golang: regexp/syntax: limit memory used by parsing regexps</li> (CVE-2022-41715)<br><li> openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher (CVE-2023-0296)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.