Critical: Release of OpenShift Serverless 1.31.1
Critical: Release of OpenShift Serverless Client kn 1.31.1 security update
Important: Release of openshift-serverless-clients kn 1.33.0 security update & enhancements
Important: Release of OpenShift Serverless Logic 1.33.0 security update & enhancements
Important: Release of OpenShift Serverless Logic 1.34.0 security update & enhancements
Important: Release of OpenShift Serverless Logic 1.30.0 SP1 security update
Important: Release of OpenShift Serverless Client kn 1.30.1 security update
Moderate: Release of OpenShift Serverless 1.32.0
Moderate: Release of OpenShift Serverless 1.33.0 security update & enhancements
Moderate: Release of OpenShift Serverless Logic 1.35.0 security update & enhancements
Moderate: Release of OpenShift Serverless Logic 1.36.0 security update & enhancements
Version 1.33.1 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.12, 4.13, 4.14, 4.15 and 4.16This release includes security, bug fixes, and enhancements.Security Fix(es): golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789) golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790) go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104) golang: net: malformed DNS message can cause infinite loop (CVE-2024-24788) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section.
Red Hat OpenShift Serverless 1.13.0 is a generally available release of theOpenShift Serverless Operator.This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform version 4.6, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.Security Fix(es): jwt-go: access restriction bypass vulnerability (CVE-2020-26160) For more details about the security issues and their impact, the CVSSscore, acknowledgements, and other related information, see the CVE pageslisted in the References section.
This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6, 4.7, 4.8, and 4.9, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.<br>Security Fix(es):<br><li> golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet (CVE-2021-29923)</li> <li> golang: Command-line arguments may overwrite global data (CVE-2021-38297)</li> <li> golang: archive/zip: malformed archive may cause panic or memory exhaustion (incomplete fix of CVE-2021-33196) (CVE-2021-39293)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat OpenShift Serverless 1.16.0 release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6 and 4.7, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.Security Fix(es): golang: encoding/xml: infinite loop when using xml.NewTokenDecoder with a custom TokenReader (CVE-2021-27918) golang: net/http: panic in ReadRequest and ReadResponse when reading a very large header (CVE-2021-31525) golang: archive/zip: malformed archive may cause panic or memory exhaustion (CVE-2021-33196) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat OpenShift Serverless 1.17.0 release of the OpenShift Serverless<br>Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6, 4.7 and 4.8, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.<br>Security Fix(es):<br><li> golang: crypto/tls: certificate of wrong type is causing TLS client to panic</li> (CVE-2021-34558)<br><li> golang: net: lookup functions may return invalid host names (CVE-2021-33195)</li> <li> golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)</li> <li> golang: match/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)</li> <li> golang: encoding/xml: infinite loop when using xml.NewTokenDecoder with a custom TokenReader (CVE-2021-27918)</li> <li> golang: net/<a href="http:" target="blank">http:</a> panic in ReadRequest and ReadResponse when reading a very large header (CVE-2021-31525)</li> <li> golang: archive/zip: malformed archive may cause panic or memory exhaustion (CVE-2021-33196)</li> It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless client kn 1.16.0. This has been fixed (CVE-2021-3703).<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat OpenShift Serverless release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6, 4.7, 4.8 and 4.9, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.Security Fix(es): golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat OpenShift Serverless 1.11.0 is a generally available release of theOpenShift Serverless Operator. This version of the OpenShift ServerlessOperator is supported on Red Hat OpenShift Container Platform version 4.6.Security Fix(es): golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) For more details about the security issue(s), including the impact, a CVSSscore, and other related information, see the CVE page(s) listed in theReferences section.
Red Hat OpenShift Serverless 1.9.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform version 4.5.Security Fix(es): golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586) golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Version 1.26.0 of the OpenShift Serverless Operator is supported on Red HatOpenShift Container Platform versions 4.8, 4.9, 4.10, and 4.11. This release includes security and bug fixes, and enhancements. golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191) golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565) For more details about the security issues, including the impact; a CVSS score;acknowledgments; and other related information refer to the CVE pages linked inthe References section.
Red Hat OpenShift Serverless 1.12.0 is a generally available release of theOpenShift Serverless Operator. This version of the OpenShift ServerlessOperator is supported on Red Hat OpenShift Container Platform version 4.6, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.Security Fix(es): golang: default Content-Type setting in net/http/cgi and net/http/fcgi could cause XSS (CVE-2020-24553) golang: math/big: panic during recursive division of very large numbers (CVE-2020-28362) golang: malicious symbol names can lead to code execution at build time (CVE-2020-28366) golang: improper validation of cgo flags can lead to code execution at build time (CVE-2020-28367) For more details about the security issues and their impact, the CVSSscore, acknowledgements, and other related information, see the CVE pageslisted in the References section.
Red Hat OpenShift Serverless 1.14.1 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6 and 4.7, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section.Security Fix(es): golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114) golang: cmd/go: packages using cgo can cause arbitrary code execution at build time (CVE-2021-3115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Red Hat OpenShift Serverless 1.10.2 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform version 4.5.Security Fix(es): golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114) golang: cmd/go: packages using cgo can cause arbitrary code execution at build time (CVE-2021-3115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This version of the OpenShift Serverless Operator is supported on Red Hat<br>OpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10, includes<br>security and bug fixes and enhancements. For more information, see the<br>documentation listed in the References section.<br>Security Fix(es):<br><li> golang: syscall: don't close fd 0 on ForkExec error (CVE-2021-44717)</li> <li> golang: net/<a href="http:" target="blank">http:</a> limit growth of header canonicalization cache</li> (CVE-2021-44716)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.