First published: Mon Jul 10 2023(Updated: )
As a Kubernetes user, I cannot connect easily connect services from one cluster with services on another cluster. Red Hat Application Interconnect enables me to create a service network and it allows geographically distributed services to connect as if they were all running in the same site.<br>Security Fix(es):<br><li> golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879)</li> <li> golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)</li> <li> golang: crypto/elliptic: panic caused by oversized scalar (CVE-2022-28327)</li> <li> golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)</li> <li> net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)</li> <li> golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)</li> <li> golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)</li> <li> golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)</li> <li> golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)</li> <li> golang: go/parser: Infinite loop in parsing (CVE-2023-24537)</li> <li> golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)</li> <li> golang: html/template: improper sanitization of CSS values (CVE-2023-24539)</li> <li> golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Red Hat Application Interconnect | ||
redhat/jsoncpp | <1.9.4-3.el9 | 1.9.4-3.el9 |
redhat/libwebsockets | <4.3.1-1.el9a | 4.3.1-1.el9a |
redhat/qpid-proton | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/skupper-cli | <1.4.1-2.el9 | 1.4.1-2.el9 |
redhat/skupper-router | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/jsoncpp | <1.9.4-3.el9 | 1.9.4-3.el9 |
redhat/jsoncpp-debuginfo | <1.9.4-3.el9 | 1.9.4-3.el9 |
redhat/jsoncpp-debugsource | <1.9.4-3.el9 | 1.9.4-3.el9 |
redhat/jsoncpp-devel | <1.9.4-3.el9 | 1.9.4-3.el9 |
redhat/libwebsockets-debuginfo | <4.3.1-1.el9a | 4.3.1-1.el9a |
redhat/libwebsockets-debugsource | <4.3.1-1.el9a | 4.3.1-1.el9a |
redhat/libwebsockets-devel | <4.3.1-1.el9a | 4.3.1-1.el9a |
redhat/python3-qpid-proton | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/python3-qpid-proton-debuginfo | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-c | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-c-debuginfo | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-c-devel | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-cpp | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-cpp-debuginfo | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-cpp-devel | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-debuginfo | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/qpid-proton-debugsource | <0.37.0-2.el9a | 0.37.0-2.el9a |
redhat/skupper-cli | <1.4.1-2.el9 | 1.4.1-2.el9 |
redhat/skupper-router | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/skupper-router-common | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/skupper-router-debuginfo | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/skupper-router-debugsource | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/skupper-router-docs | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/skupper-router-tools | <2.4.1-2.el9 | 2.4.1-2.el9 |
redhat/libwebsockets | <4.3.1-1.el8a | 4.3.1-1.el8a |
redhat/qpid-proton | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/skupper-cli | <1.4.1-2.el8 | 1.4.1-2.el8 |
redhat/skupper-router | <2.4.1-2.el8 | 2.4.1-2.el8 |
redhat/libwebsockets-debuginfo | <4.3.1-1.el8a | 4.3.1-1.el8a |
redhat/libwebsockets-debugsource | <4.3.1-1.el8a | 4.3.1-1.el8a |
redhat/libwebsockets-devel | <4.3.1-1.el8a | 4.3.1-1.el8a |
redhat/python3-qpid-proton | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/python3-qpid-proton-debuginfo | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/qpid-proton-c | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/qpid-proton-c-debuginfo | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/qpid-proton-c-devel | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/qpid-proton-cpp-debuginfo | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/qpid-proton-debuginfo | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/qpid-proton-debugsource | <0.37.0-2.el8a | 0.37.0-2.el8a |
redhat/skupper-cli | <1.4.1-2.el8 | 1.4.1-2.el8 |
redhat/skupper-router | <2.4.1-2.el8 | 2.4.1-2.el8 |
redhat/skupper-router-common | <2.4.1-2.el8 | 2.4.1-2.el8 |
redhat/skupper-router-debuginfo | <2.4.1-2.el8 | 2.4.1-2.el8 |
redhat/skupper-router-debugsource | <2.4.1-2.el8 | 2.4.1-2.el8 |
redhat/skupper-router-docs | <2.4.1-2.el8 | 2.4.1-2.el8 |
redhat/skupper-router-tools | <2.4.1-2.el8 | 2.4.1-2.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.