RHSA-2024:0843: Critical: Release of OpenShift Serverless 1.31.1
Critical: Release of OpenShift Serverless 1.31.1
Other sources
Version 1.31.1 of the OpenShift Serverless Operator is supported on Red Hat<br>OpenShift Container Platform versions 4.11, 4.12, 4.13 and 4.14<br>This release includes security, bug fixes, and enhancements.<br>Security Fix(es):<br><li> go-git: Maliciously crafted Git server replies can cause DoS on go-git clients (CVE-2023-49568)</li> <li> go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients (CVE-2023-49569)</li> <li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795)</li> <li> logback: A serialization vulnerability in logback receiver (CVE-2023-6481)</li> For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0843?
RHSA-2024:0843 is classified as a critical vulnerability affecting Red Hat OpenShift Serverless.
How do I fix RHSA-2024:0843?
To fix RHSA-2024:0843, users should upgrade to the supported version of OpenShift Serverless specified in the advisory.
Which versions of OpenShift are affected by RHSA-2024:0843?
RHSA-2024:0843 affects Red Hat OpenShift Serverless versions that run on versions 4.11, 4.12, 4.13, and 4.14.
What security fixes are included in RHSA-2024:0843?
RHSA-2024:0843 includes multiple security fixes that enhance the security posture of the OpenShift Serverless platform.
Is RHSA-2024:0843 specific to any hardware architecture?
Yes, RHSA-2024:0843 is applicable to Red Hat OpenShift Serverless on IBM Z, LinuxONE, and IBM Power architectures.