First published: Thu May 18 2023(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments.<br>Security Fix(es):<br><li> mongo-go-driver: specific cstrings input may not be properly validated</li> (CVE-2021-20329)<br><li> golang: out-of-bounds read in golang.org/x/text/language leads to DoS</li> (CVE-2021-38561)<br><li> golang: net/<a href="http:" target="_blank">http:</a> excessive memory growth in a Go server accepting HTTP/2</li> requests (CVE-2022-41717)<br>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:1328 is rated as moderate due to the potential for input validation issues.
To fix RHSA-2023:1328, update the mongo-go-driver to the latest version where the input validation issue has been addressed.
RHSA-2023:1328 specifically addresses the input validation vulnerability identified as CVE-2021-20329.
You should verify if you are using the affected version of the mongo-go-driver to determine if RHSA-2023:1328 applies to your system.
For more information about RHSA-2023:1328, refer to the relevant advisory and associated documentation from Red Hat.