First published: Mon Dec 12 2022(Updated: )
Red Hat OpenShift Serverless Client kn 1.26.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.26.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms.<br>Security Fix(es):<br><li> golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)</li> For more details about the security issue(s), including the impact; a CVSS<br>score; acknowledgments; and other related information refer to the CVE page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openshift-serverless-clients | <1.5.0-3.el8 | 1.5.0-3.el8 |
redhat/openshift-serverless-clients | <1.5.0-3.el8 | 1.5.0-3.el8 |
redhat/openshift-serverless-clients | <1.5.0-3.el8 | 1.5.0-3.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:8932 is classified as low.
To fix RHSA-2022:8932, upgrade to the remedied version 1.5.0-3.el8 of the openshift-serverless-clients package.
RHSA-2022:8932 affects the openshift-serverless-clients package version up to 1.5.0-3.el8 on RHEL platforms.
The impact of RHSA-2022:8932 includes a crash vulnerability in the Go programming language used in the kn CLI.
There are no specific workarounds mentioned for RHSA-2022:8932; upgrading is recommended.