RHSA-2024:0880: Critical: Release of OpenShift Serverless Client kn 1.31.1 security update
Critical: Release of OpenShift Serverless Client kn 1.31.1 security update
Other sources
Red Hat OpenShift Serverless Client kn 1.31.1 provides a CLI to interact with<br>Red Hat OpenShift Serverless 1.31.1. The kn CLI is delivered as an RPM package<br>for installation on RHEL platforms, and as binaries for non-Linux platforms.<br>This release includes security, bug fixes, and enhancements.<br>Security Fix(es):<br><li> go-git: Maliciously crafted Git server replies can cause DoS on go-git clients (CVE-2023-49568)</li> <li> go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients (CVE-2023-49569)</li> <li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795)</li> A Red Hat Security Bulletin, which addresses further details about the Rapid<br>Reset flaw is available in the References section.<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0880?
RHSA-2024:0880 is classified as a critical vulnerability.
How do I fix RHSA-2024:0880?
To fix RHSA-2024:0880, update to 'openshift-serverless-clients' version 1.10.0-6.el8.
Which products are affected by RHSA-2024:0880?
RHSA-2024:0880 affects various versions of Red Hat OpenShift Serverless and its CLI tools.
Is there a workaround for RHSA-2024:0880?
Currently, there is no specified workaround for RHSA-2024:0880 other than applying the security update.
What does the RHSA-2024:0880 update address?
The RHSA-2024:0880 update addresses security vulnerabilities in the OpenShift Serverless Client kn.