Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Red Hat OpenShift Serverless 1.17.0 RHSA-2021:3555-01 Moderate Threat

red hat
Calendar Grey September 16, 2021
Dist Redhat Esm H88
The announcement of version 1.17.0 for OpenShift Serverless Client by Red Hat indicates a significant security concern.
Release of OpenShift Serverless Client kn 1.17.0 Red Hat Product Security has rated this update as having a security impact of Moderate

Solution

See the Red Hat OpenShift Container Platform 4.6 documentation at: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21 4.6/html/serverless/index See the Red Hat OpenShift Container Platform 4.7 documentation at: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21 4.7/html/serverless/index See the Red Hat OpenShift Container Platform 4.8 documentation at: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21 4.8/html/serverless/index

Summary

Red Hat OpenShift Serverless Client kn 1.17.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.17.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms.
Security Fix(es):
* serverless: incomplete fix for CVE-2021-27918 / CVE-2021-31525 / CVE-2021-33196 (CVE-2021-3703)
* golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558) * golang: net: lookup functions may return invalid host names (CVE-2021-33195) * golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197) * golang: match/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-3703 https://access.redhat.com/security/cve/CVE-2021-27918 https://access.redhat.com/security/cve/CVE-2021-31525 https://access.redhat.com/security/cve/CVE-2021-33195 https://access.redhat.com/security/cve/CVE-2021-33196 https://access.redhat.com/security/cve/CVE-2021-33197 https://access.redhat.com/security/cve/CVE-2021-33198 https://access.redhat.com/security/cve/CVE-2021-34558 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33

Package List

Openshift Serverless 1 on RHEL 8Base:
Source: openshift-serverless-clients-0.23.2-1.el8.src.rpm
ppc64le: openshift-serverless-clients-0.23.2-1.el8.ppc64le.rpm
s390x: openshift-serverless-clients-0.23.2-1.el8.s390x.rpm
x86_64: openshift-serverless-clients-0.23.2-1.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key


Advisory ID: RHSA-2021:3555-01
Product: Red Hat OpenShift Serverless
Issue date: 2021-09-16

Topic

Release of OpenShift Serverless Client kn 1.17.0Red Hat Product Security has rated this update as having a security impactofModerate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVElink(s) in the References section.

Relevant Releases Architectures

Openshift Serverless 1 on RHEL 8Base - ppc64le, s390x, x86_64

Bugs Fixed

1983596 - CVE-2021-34558 golang: crypto/tls: certificate of wrong type is causing TLS client to panic

1983656 - Release of Openshift Serverless Client 1.17.0

1989564 - CVE-2021-33195 golang: net: lookup functions may return invalid host names

1989570 - CVE-2021-33197 golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty

1989575 - CVE-2021-33198 golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents

1992955 - CVE-2021-3703 serverless: incomplete fix for CVE-2021-27918 / CVE-2021-31525 / CVE-2021-33196

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here