-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: Release of OpenShift Serverless Client kn 1.29.1
Advisory ID:       RHSA-2023:4471-01
Product:           Red Hat OpenShift Serverless
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:4471
Issue date:        2023-08-03
CVE Names:         CVE-2023-3089 
=====================================================================

1. Summary:

Red Hat OpenShift Serverless 1.29.1 is now available.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Openshift Serverless 1 on RHEL 8Base - ppc64le, s390x, x86_64

3. Description:

Red Hat OpenShift Serverless Client kn 1.29.1 provides a CLI to interact
with Red Hat OpenShift Serverless 1.29.1. The kn CLI is delivered as an RPM
package for installation on RHEL platforms, and as binaries for non-Linux
platforms.

This release includes security and bug fixes, and enhancements.

Security Fix(es):

* openshift: OCP & FIPS mode (CVE-2023-3089)

For more information about CVE-2023-3089, see
https://access.redhat.com/security/vulnerabilities/RHSB-2023-001.

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgements, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For instructions on how to install and use OpenShift Serverless, see
documentation linked from the References section.

5. Bugs fixed (https://bugzilla.redhat.com/):

2212085 - CVE-2023-3089 openshift: OCP & FIPS mode

6. Package List:

Openshift Serverless 1 on RHEL 8Base:

Source:
openshift-serverless-clients-1.8.1-6.el8.src.rpm

ppc64le:
openshift-serverless-clients-1.8.1-6.el8.ppc64le.rpm

s390x:
openshift-serverless-clients-1.8.1-6.el8.s390x.rpm

x86_64:
openshift-serverless-clients-1.8.1-6.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2023-3089
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/security/vulnerabilities/RHSB-2023-001
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.10/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.11/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.12/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.13/html/serverless/index

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJkzAxKAAoJENzjgjWX9erEO5cQAKhOGMfA3elNcWkiSUkqi95v
leDH0tONGAVdgZoTnYW1hGXMqoDin1rwijHLVcD5DZt/VNPElvPzmrGmvRajgE7C
QDZmz6Kg4SPj3mScJPrJogiNMFRnBuqiSPCtzvpKDE9n2gYz88lSOFzxHVEbuP6c
6TEGzsz8ZDbPkmiSE+T4wpbDszn6gDOpwaJWTlgSqFXV68IoMCD+V9+5Nqg3dNVJ
1NWf6OrrqFdBw5uIC2l6HSVuEdHVF8Udzq3LuEAOVL+/fAVqlz+X4KFJFLKgqmrB
3+7r7zi3UJ77qKQBgd6ZMqUlt8bu9Vw3+5987wyjQBxqiHmhmosBw3wK4s/y3kBD
qO3ShcCo5hYgCiebgfUZvUl2IFr0ZuzXoa0hMfdlmT+FFaNBvgvKA/8F0dLiKEuF
30pBokKuOvRpYNHHaXnRLIK9NIZcVO5zBpO9rKLeitqZAh//6sVgSoEQnY8znGjq
lRAdK82C5jXeQb5gHqN6v4+gbWp0C5g5IWQl7P4lzqnq/BmvAxhq/5SHpIfg2+P6
K/7y+OSA+OGDcAROYK/tthJimXBjF7KAPvGG41F/XmhOMOUH2zXU/w+CBfgPWisz
sS/UHG0i0lM/YTeS0RoSGa56fVfTzt4snysGYY6UGmjwJzZQR5VOfLLba6a7+nsS
Y3VYSnzLk2qz++F29YcY
=ojGB
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-4471:01 Moderate: Release of OpenShift Serverless Client

Red Hat OpenShift Serverless 1.29.1 is now available

Summary

Red Hat OpenShift Serverless Client kn 1.29.1 provides a CLI to interact with Red Hat OpenShift Serverless 1.29.1. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms.
This release includes security and bug fixes, and enhancements.
Security Fix(es):
* openshift: OCP & FIPS mode (CVE-2023-3089)
For more information about CVE-2023-3089, see https://access.redhat.com/security/vulnerabilities/RHSB-2023-001.
For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For instructions on how to install and use OpenShift Serverless, see documentation linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 https://access.redhat.com/documentation/en-us/openshift_container_platform/4.10/html/serverless/index https://access.redhat.com/documentation/en-us/openshift_container_platform/4.11/html/serverless/index https://access.redhat.com/documentation/en-us/openshift_container_platform/4.12/html/serverless/index https://access.redhat.com/documentation/en-us/openshift_container_platform/4.13/html/serverless/index

Package List

Openshift Serverless 1 on RHEL 8Base:
Source: openshift-serverless-clients-1.8.1-6.el8.src.rpm
ppc64le: openshift-serverless-clients-1.8.1-6.el8.ppc64le.rpm
s390x: openshift-serverless-clients-1.8.1-6.el8.s390x.rpm
x86_64: openshift-serverless-clients-1.8.1-6.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2023:4471-01
Product: Red Hat OpenShift Serverless
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4471
Issued Date: : 2023-08-03
CVE Names: CVE-2023-3089

Topic

Red Hat OpenShift Serverless 1.29.1 is now available.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Openshift Serverless 1 on RHEL 8Base - ppc64le, s390x, x86_64


Bugs Fixed

2212085 - CVE-2023-3089 openshift: OCP & FIPS mode


Related News