First published: Thu Nov 03 2022(Updated: )
Service Binding Operator 1.3.1 is now available for OpenShift Developer Tools and Services for OCP 4.9 +<br>Security Fix(es):<br><li> golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags (CVE-2022-32149)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
=1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:7407 is classified as moderate.
RHSA-2022:7407 addresses a performance issue in golang.org/x/text/language related to CVE-2022-32149.
To fix RHSA-2022:7407, update your OpenShift Developer Tools and Services to version 1.3.1 or later.
RHSA-2022:7407 affects OpenShift Container Platform 4.9 and newer versions.
There are no specific workarounds recommended for the issue identified in RHSA-2022:7407.