An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.9. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Service Binding Operator security update Advisory ID: RHSA-2023:0918-01 Product: OpenShift Developer Tools and Services Advisory URL: https://access.redhat.com/errata/RHSA-2023:0918 Issue date: 2023-02-27 CVE Names: CVE-2021-46848 CVE-2022-1304 CVE-2022-22624 CVE-2022-22628 CVE-2022-22629 CVE-2022-22662 CVE-2022-26700 CVE-2022-26709 CVE-2022-26710 CVE-2022-26716 CVE-2022-26717 CVE-2022-26719 CVE-2022-30293 CVE-2022-35737 CVE-2022-40303 CVE-2022-40304 CVE-2022-41717 CVE-2022-42898 CVE-2022-47629 ==================================================================== 1. Summary: An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Service Binding manages the data plane for applications and backing services. Security Fix(es): * golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the Referencessection. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2161274 - CVE-2022-41717 golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): APPSVC-1204 - Provisioned Service discovery APPSVC-1256 - CVE-2022-41717 6. References: https://access.redhat.com/security/cve/CVE-2021-46848 https://access.redhat.com/security/cve/CVE-2022-1304 https://access.redhat.com/security/cve/CVE-2022-22624 https://access.redhat.com/security/cve/CVE-2022-22628 https://access.redhat.com/security/cve/CVE-2022-22629 https://access.redhat.com/security/cve/CVE-2022-22662 https://access.redhat.com/security/cve/CVE-2022-26700 https://access.redhat.com/security/cve/CVE-2022-26709 https://access.redhat.com/security/cve/CVE-2022-26710 https://access.redhat.com/security/cve/CVE-2022-26716 https://access.redhat.com/security/cve/CVE-2022-26717 https://access.redhat.com/security/cve/CVE-2022-26719 https://access.redhat.com/security/cve/CVE-2022-30293 https://access.redhat.com/security/cve/CVE-2022-35737 https://access.redhat.com/security/cve/CVE-2022-40303 https://access.redhat.com/security/cve/CVE-2022-40304 https://access.redhat.com/security/cve/CVE-2022-41717 https://access.redhat.com/security/cve/CVE-2022-42898 https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIUAwUBY/xNo9zjgjWX9erEAQh2XA/1H4kyOvgq1wB/cW41Sczdbljxq0R5nJ5d H0LQm3vxbU7g5I327U6PGso+4Z2Z5NoiZLruXCca/KMko7O2v5AP8e4rYV0LYOeI 7HOgXPMBJRcyGEcPXPgNR6HEHAr/BKyLlTbl6tZ9sPItMhSv5eKUMjtTAggNCNiQ DPCwNr5o7HK0qDr4B41Y5kSPaOFl41rDB0Xbq9WigkUYmal8WBJ7xp76zvdYc3Uu e34OGMrQVqw8apJUyJUlH4WOU3hs/I8oCuyJuecIYuVWtft65m5Bk2ZqEHTgMmA0 5pXDcw/lhIgC/yofVWQQ41rRmIcR1VJAJ0mz1gsPC8f/gHE4hqlXIlLIUezslWoR kgaKARfjm7rLAB3JUzcKqU1a1IuYNOGZW1wkPC6PFADAkSjsn0OxLXoyFM/aYMsf 8eTQ+Pkv7hO3OCC/db42YlN+7QtFYxwlgxVnNEvY+e3LMfVLDbIWPv0Mydl+YDaR mLpIWm/NYkTD5esDA3yDdB6lhrpqU30ISkWniMaQ+6mvcZakhytGOWaQ42yeV4QA uVuKKPj1CsPcodzLhfvIa3uNenqjsdYQ27MztJGdyPGuozjJjxRqsSblH7oAI56d pBJ0nwmFQFfQVVNgPN77jpIDLGoUyqGBtwYr0p02aufJIHDq+ANaL31Qq3QaRmlJ VRjZbVTZfw==6W66 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.9. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Service Binding Operator 1.3.1 security update Advisory ID: RHSA-2022:7407-01 Product: OpenShift Developer Tools and Services Advisory URL: https://access.redhat.com/errata/RHSA-2022:7407 Issue date: 2022-11-03 CVE Names: CVE-2020-35525 CVE-2020-35527 CVE-2022-2509 CVE-2022-3515 CVE-2022-32149 CVE-2022-37434 ==================================================================== 1. Summary: An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Service Binding Operator 1.3.1 is now available for OpenShift Developer Tools and Services for OCP 4.9 + Security Fix(es): * golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags (CVE-2022-32149) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details on how to apply this update, see: https://access.redhat.com/articles/11258. Follow the instructions linked in the References section tocreate service binding connections between applications and services using the Developer perspective in the OpenShift Container Platform web console. 4. Bugs fixed (https://bugzilla.redhat.com/): 2134010 - CVE-2022-32149 golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): APPSVC-1220 - Fix CVE-2022-32149 6. References: https://access.redhat.com/security/cve/CVE-2020-35525 https://access.redhat.com/security/cve/CVE-2020-35527 https://access.redhat.com/security/cve/CVE-2022-2509 https://access.redhat.com/security/cve/CVE-2022-3515 https://access.redhat.com/security/cve/CVE-2022-32149 https://access.redhat.com/security/cve/CVE-2022-37434 https://access.redhat.com/security/updates/classification/#moderate https://docs.openshift.com/en/container-platform/4.14/applications/connecting_applications_to_services/odc-connecting-an-application-to-a-service-using-the-developer-perspective.html 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY2QOrdzjgjWX9erEAQjn+A//X6hSXPC7IwDSYPPbFS3+dzfmnysoy/zd F+yf+uHWgtf4iIJgcqrwqo0Trc9tPqauN6JuBYvROdiK4qJPJm7ni8jme4EU34mx EX4reTVrltLti8Dhv1G9CrtHZic9dxV9zZrxbMP16BaNlHkhlvi5q6JipZLTc+qU KlLr79UN/cBfzfKYc53Nbfej+q4GbG97imnOysKozP+v5YN7f9SLycFoxIo1tv53 kQGNdWpFBE7AAhd28fn0iXK8D1Y9FW//xahuJAH+NA/oIjbFRRmwGMxaeANo88Cy jqUoCXCykAmOsKiFHXiD4fu/TsmAkHUuguwzrZvtlapjpKDCKKPiOD4G/uBMyhtb dXH+2kMOMNRA38LMFHKCsltPHqPzKiMS5UnYk6w7yXDl7IW/45rt0HrK70/Yt9jr 22XrvLnYSMHStEzhPcxHuUAt1m2bVk67XMYfH5luQRdKbdG+nMWx9ekA8Fhyebax nRpNDPdbETleXS4NMXACtVkaT/ps7JnrrhbsXB4bW4tAj8l5ryUeNu0aA+6uZo3K Om2MES7KriMsCvU93v8/AmIxtMERAVHxPlo230bB4y4MQiA0l3IxGViRZdDM5N2p 7acUjOyNm6PvsZQ33gDgH4pwddBIaAOu/nDJUAzHPqFrPTmrHmMe/OGPo9sb6QEq oTqLGhQ76lU=CnnY -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.7 + Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Service Binding Operator security update Advisory ID: RHSA-2022:5525-01 Product: OpenShift Developer Tools and Services Advisory URL: https://access.redhat.com/errata/RHSA-2022:5525 Issue date: 2022-07-07 CVE Names: CVE-2021-3634 CVE-2021-38561 CVE-2022-1271 ==================================================================== 1. Summary: An update for service-binding-operator-bundle-container and service-binding-operator-container is now available for OpenShift Developer Tools and Services for OCP 4.7 + Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Security Fix(es): * golang: out-of-bounds read in golang.org/x/text/language leads to DoS (CVE-2021-38561) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2100495 - CVE-2021-38561 golang: out-of-bounds read in golang.org/x/text/language leads to DoS 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): APPSVC-1133 - Release 1.1.1 version APPSVC-1135 - Unable to retrieve ClusterWorkloadResourceMappingon Dev Sandbox 6. References: https://access.redhat.com/security/cve/CVE-2021-3634 https://access.redhat.com/security/cve/CVE-2021-38561 https://access.redhat.com/security/cve/CVE-2022-1271 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/building_applications/connecting-applications-to-services#odc-connecting-an-application-to-a-service-using-the-developer-perspective 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYuFkJdzjgjWX9erEAQjhEw//XlUtHhyuggxKokpYs+fX89eRq1CmRc09 4fTkFg9i3ORKsv+y/4ZIP64CO0qLJAxqNQLEKRtcmrXnE6pb8EPwP7nD0fMSRM6d fK5oI1wQWwQnihK6UGwqD9MZ52EJQxQiEhVfsk4o0AsSFl0FWwJiuJvHjhfDT4eU PlDmp8NAA/JwmunxWgqk4Dob2KLY3eVyMJb4Ew55NvDHhSQ+mOqKBfGAm56UV1y0 bOOnLJupw+5N7ZA9UoAvG+QJf8HzV7/4MNpK1WfzdDsxJVtowTsfgkIdB+gvRXGx NNpAZKFAoqtm9jYdotEDV+1rPVKXIviDfu50fCPWks6dHsYpTryw7ttyuZJXIpje bVRSXvsBAtmip9AOKl6NjyMmYpPfhQ30YmOXl+Kvdm2hTND+vTZNUpVXSiGdymTl 9/LDa1ReQGNPeGSttQG1KEgtY+f9xzhT/uCd9U3ryblJQle5BuHIeU4qryslr8AW /13VAqcawo1yHwfXEulbTfc6EA0NRA5CrppvUtGXzarWKPi+Jxnf2oOG0c+jnDqf N/prveS4OtCivLW2zX5Lur7e49BX5VWCXmKkkQDSJHRQjnF1Gpe3XIhkyPULSfjN 9CdqDb5eGYXzE2MkXvqXmjZHT4Q4C9iJKR7r/QXfFtKVN5PR9VKzDm7+Xi3wNuCj BIz1LVR6q04=C2mi -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.