Version 1.30.2 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.11, 4.12, and 4.13.This release includes security, bug fixes, and enhancements.Security Fix(es): HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325) golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409) golang: net/http: insufficient sanitization of Host header (CVE-2023-29406) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section.
Version 1.27.1 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.8, 4.9, 4.10, 4.11 and 4.12.This release includes security and bug fixes, and enhancements.Security Fixes in this release include: golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests(CVE-2022-41717) For more details about the security issues, including the impact; a CVSS score; acknowledgments; and other related information refer to the CVE pages linked in the References section.
Version 1.27.0 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.8, 4.9, 4.10, 4.11 and 4.12. This release includes security and bug fixes, and enhancements. golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715) golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664) golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880) golang: archive/tar: unbounded memory consumption when reading headers (CVE-2022-2879) For more details about the security issues, including the impact; a CVSS score;acknowledgments; and other related information refer to the CVE pages linked in the References section.
Version 1.22.1 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10. This release includes security and bug fixes, and enhancements.Security Fixes in this release include: golang: crypto/elliptic IsOnCurve returns true for invalid field elements(CVE-2022-23806) golang: cmd/go: misinterpretation of branch names can lead to incorrect access control(CVE-2022-23773) golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString (CVE-2022-23772) For more details about the security issues, including the impact; a CVSS score; acknowledgments; and other related information refer to the CVE pages linked in the References section.
Version 1.22.0 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10. This release includes security and bug fixes and enhancements. For more information, see the documentation linked in the Solution section.Security Fixes in this release include: golang: archive/zip: Reader.Open panics on empty string (CVE-2021-41772) golang: debug/macho: invalid dynamic symbol table command can cause panic (CVE-2021-41771) For more details about the security issues, including the impact, a CVSSscore, acknowledgments, and other related information refer to the CVE pageslinked in the References section.
Red Hat OpenShift Serverless 1.14.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6 and 4.7, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.Security Fix(es): golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114) golang: cmd/go: packages using cgo can cause arbitrary code execution at build time (CVE-2021-3115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.