- Issued:
- 2023-06-05
- Updated:
- 2023-06-05
RHSA-2023:3455 - Security Advisory
Synopsis
Moderate: Release of OpenShift Serverless 1.29.0
Type/Severity
Security Advisory: Moderate
Topic
OpenShift Serverless version 1.29.0 contains a moderate security impact.
The References section contains CVE links providing detailed severity ratings
for each vulnerability. Ratings are based on a Common Vulnerability Scoring
System (CVSS) base score.
Description
Version 1.29.0 of the OpenShift Serverless Operator is supported on Red Hat
OpenShift Container Platform versions 4.10, 4.11, 4.12, and 4.13.
This release includes security and bug fixes, and enhancements.
Security Fixes in this release include:
- containerd: Supplementary groups are not set up properly(CVE-2023-25173)
- golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding(CVE-2022-41723)
- golang: net/http, mime/multipart: denial of service from excessive resource consumption(CVE-2022-41725)
- golang: crypto/tls: large handshake records may cause panics(CVE-2022-41724)
- golang: html/template: backticks not treated as string delimiters(CVE-2023-24538)
- golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption(CVE-2023-24536)
- golang: net/http, net/textproto: denial of service from excessive memory allocation(CVE-2023-24534)
- golang: go/parser: Infinite loop in parsing(CVE-2023-24537)
For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, see the CVE pages linked from the References section.
Solution
For instructions on how to install and use OpenShift Serverless, see documentation linked from the References section.
Affected Products
- Red Hat Openshift Serverless 1 x86_64
- Red Hat OpenShift Serverless for IBM Power, little endian 1 ppc64le
- Red Hat OpenShift Serverless for IBM Z and LinuxONE 1 s390x
Fixes
- BZ - 2174485 - CVE-2023-25173 containerd: Supplementary groups are not set up properly
- BZ - 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
- BZ - 2178488 - CVE-2022-41725 golang: net/http, mime/multipart: denial of service from excessive resource consumption
- BZ - 2178492 - CVE-2022-41724 golang: crypto/tls: large handshake records may cause panics
- BZ - 2184481 - CVE-2023-24538 golang: html/template: backticks not treated as string delimiters
- BZ - 2184482 - CVE-2023-24536 golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption
- BZ - 2184483 - CVE-2023-24534 golang: net/http, net/textproto: denial of service from excessive memory allocation
- BZ - 2184484 - CVE-2023-24537 golang: go/parser: Infinite loop in parsing
- BZ - 2185507 - Release of OpenShift Serverless Serving 1.29.0
- BZ - 2185509 - Release of OpenShift Serverless Eventing 1.29.0
CVEs
- CVE-2022-4304
- CVE-2022-4450
- CVE-2022-36227
- CVE-2022-41723
- CVE-2022-41724
- CVE-2022-41725
- CVE-2023-0215
- CVE-2023-0286
- CVE-2023-0361
- CVE-2023-0767
- CVE-2023-21930
- CVE-2023-21937
- CVE-2023-21938
- CVE-2023-21939
- CVE-2023-21954
- CVE-2023-21967
- CVE-2023-21968
- CVE-2023-24534
- CVE-2023-24536
- CVE-2023-24537
- CVE-2023-24538
- CVE-2023-25173
- CVE-2023-27535
References
- https://access.redhat.com/security/updates/classification/#moderate
- https://access.redhat.com/documentation/en-us/openshift_container_platform/4.10/html/serverless/index
- https://access.redhat.com/documentation/en-us/openshift_container_platform/4.11/html/serverless/index
- https://access.redhat.com/documentation/en-us/openshift_container_platform/4.12/html/serverless/index
- https://access.redhat.com/documentation/en-us/openshift_container_platform/4.13/html/serverless/index
ppc64le
openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:f966dad57c447679c733737de54808aa4ba2fa0f274a94ed6779d6e16b8d39f1 |
openshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8@sha256:4dcfd50432a5124d315fff9355ca9b2add081a0ece3d572f85c571b007f026c8 |
openshift-serverless-1/client-kn-rhel8@sha256:3a817fd0ca3e1b09452eeee0b0d558a135d1df60eb37c1422651da5a33fdf741 |
openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:e5f76ed2888d97df2a964d3116bb16ae217ca45bb735ecd265a979681a9c5264 |
openshift-serverless-1/eventing-controller-rhel8@sha256:aa45563b2ac89e6b8180cfa2119a34023dd139c7c4a94d581576ad474db1469d |
openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:c35482e886ecfedf85be13d66bf4d78dde85c32a6463cb7d5496f17432834d0c |
openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:ba494328e98f5724333c1368c2438bd1cf81bbaa58beefd913a71ce67084332c |
openshift-serverless-1/eventing-kafka-broker-controller-rhel8@sha256:2b085ff2bf8763b611398579d12fc55adbec304dd6c2b4bf6a584aedf76c2e9d |
openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8@sha256:a73d775ef66925fe2f605b13667bf7dad0d806f813a6141cca2a57fc1e05f7a6 |
openshift-serverless-1/eventing-kafka-broker-post-install-rhel8@sha256:38ede979b0aa76cbef2dcc0493b40a28caf077175c6aeb65f2f4c19aebf7606a |
openshift-serverless-1/eventing-kafka-broker-receiver-rhel8@sha256:3c4593c6d8560b0a80f3bcbd12b851fe8386d768e4afdabd83812ae7da87b8ae |
openshift-serverless-1/eventing-kafka-broker-webhook-rhel8@sha256:95adf0b159c4c27eb11776bad0e86753c0c66e91b5adc96d1b799b7320b8e5e2 |
openshift-serverless-1/eventing-mtbroker-filter-rhel8@sha256:d466a0e8ba109a2ef0ff6b76da86b5d5ccc79b233e981249074ecff8f7f26a94 |
openshift-serverless-1/eventing-mtbroker-ingress-rhel8@sha256:ad51a8be11a37569c04b737a16ae14d40dc8e34e7e88c0f4a5ea1509a394a9ab |
openshift-serverless-1/eventing-mtchannel-broker-rhel8@sha256:af9b74ad8f7342e081de0312b015baedae9edbcf6a838ee36a35e2780590d9d3 |
openshift-serverless-1/eventing-mtping-rhel8@sha256:7b4bc2943a3109143c890bfe0d4bfb82975f3a3a6e5fbf30e15ccb1817ea9422 |
openshift-serverless-1/eventing-storage-version-migration-rhel8@sha256:aa556f42cd68137c53da9d11e16ea86808101545541bf6bcfc082b27ce9ebb9b |
openshift-serverless-1/eventing-webhook-rhel8@sha256:f94f5eca225561a177b1446eca01949e0ca4668709b68cb430a8337bed609628 |
openshift-serverless-1/func-utils-rhel8@sha256:260d4448741c71a59c3ea0485fa1f5da27a1703a6141cb0ac67551787ba88207 |
openshift-serverless-1/ingress-rhel8-operator@sha256:da4c3d9405fd92c2a7c3e9749696b1a1e7501ab8f359e0d2b5ad88287b0ea558 |
openshift-serverless-1/kn-cli-artifacts-rhel8@sha256:85bd2ef36650b2e9a36f53973fcb8a4234b30946ca5fb36d967b60918d874a62 |
openshift-serverless-1/knative-rhel8-operator@sha256:8d5d3ae5d4cb6f1195d8a1b3b03373b3f1fd60a25de9769946e67128646b08fe |
openshift-serverless-1/kourier-control-rhel8@sha256:c089a5b3a964aea2c9d756e3d944ef94cf9150521394ae8555e65612fc6840c0 |
openshift-serverless-1/net-istio-controller-rhel8@sha256:495435b529ba9304cac0bd7b6e8c29f2f239e1e64eb97b8502823ff6a6fdcb4f |
openshift-serverless-1/net-istio-webhook-rhel8@sha256:0949dbdd4688ad7e69156b5e57804711ae109f37813fcbd353ca960979ba0c6e |
openshift-serverless-1/serverless-rhel8-operator@sha256:e7dc51b6cc857b90afffd0dd77bd11a39297d863673e984930a876ee4fb1f14b |
openshift-serverless-1/serving-activator-rhel8@sha256:e02d635208145f4a2c8dc71cffbfbfcadd1efac8df869f332ccbed766ea80f60 |
openshift-serverless-1/serving-autoscaler-hpa-rhel8@sha256:d9dfc582479d13970f281899c14c4b581f81d96a761cadb0b86e806fc630f6eb |
openshift-serverless-1/serving-autoscaler-rhel8@sha256:f184c8e4647dc78dbb06b50362e2c298788abc3e297e4d67a67332966a1fa34c |
openshift-serverless-1/serving-controller-rhel8@sha256:2b94cfb99c4a0422117f78025471d1080f08533c45ae2f94cbe30bc6891520ba |
openshift-serverless-1/serving-domain-mapping-rhel8@sha256:3136eb55b154072b382f7984071f752d10517a089b74ed9d24bd2100cc976761 |
openshift-serverless-1/serving-domain-mapping-webhook-rhel8@sha256:3c546fe4199ca2805dc2c91d5aaae564eb30ed75f6c4bfd38e4e1d928c141bcf |
openshift-serverless-1/serving-queue-rhel8@sha256:a1c8b2dd7d1bd1271ff8eb1d1a2210690062ba2a9228bfb5baee1499edd08111 |
openshift-serverless-1/serving-storage-version-migration-rhel8@sha256:4903b39a6100dfdee22ec9210a2b903a76e719e90f60f6899a3afa9be96cb1cd |
openshift-serverless-1/serving-webhook-rhel8@sha256:3cf1a479ae3eb8fc5ed40b8549e4f792bbcbc435a9771b2548a16b1221d9a0d5 |
openshift-serverless-1/svls-must-gather-rhel8@sha256:f696b51f34416a55c418b1227a6c4fca443e424edbb83beb2bc677ac403fa3a9 |
s390x
openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:9ce4c06789903d0b14fdb95b92b021f1a6bd37e0572639297cdf38c546e9085c |
openshift-serverless-1/client-kn-rhel8@sha256:475d3183ff0c315cc587631049355aec6e0d9cdbec546b9ea265f6f8814b34ba |
openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:5e4a8bb46db7d8b948b1604fe933e97cda0bd00ea3b8f899c315b9ba9fa34092 |
openshift-serverless-1/eventing-controller-rhel8@sha256:e68372fb2107f5bb22c639616261fcde679f8870ca12eb1100dd1c2190de75cb |
openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:34a970593de5b112683f720ae15513b8e6e1f63e3d751c72a83c7a45287ddeaf |
openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:b5ec6a25956dea49bce58f688d806a3071860f31bd1f0bff427917d9c6b20f4b |
openshift-serverless-1/eventing-kafka-broker-controller-rhel8@sha256:e7e9ab86f0fbb2950a5f63f288c7e9274683b69e6691e906b98718908b0cebc8 |
openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8@sha256:408359f26a8c04a55c6abb4f755859381620d167d318103e9d43f91d4f69dd97 |
openshift-serverless-1/eventing-kafka-broker-post-install-rhel8@sha256:f5cb79b51df9b5d04cdc5b1c32bcc574bb04c54b5f3a69b476d669e4cade3f59 |
openshift-serverless-1/eventing-kafka-broker-receiver-rhel8@sha256:4d5b34acbad345d098991ab5c0dd634d4437a49e1e70c207b29c46c6786d2e8d |
openshift-serverless-1/eventing-kafka-broker-webhook-rhel8@sha256:31796d24fd97b9c136328f8a989a9229d30d98daac5451de86f39f74e774ca78 |
openshift-serverless-1/eventing-mtbroker-filter-rhel8@sha256:6ed594aab006c1c1f5d9fcf2a345179d24079f093d1c7a9aef57e9b0514653a9 |
openshift-serverless-1/eventing-mtbroker-ingress-rhel8@sha256:23a5e5d3ee65b830413247329d271743a30e4bcb80ff58bd26662f4d8d680e9a |
openshift-serverless-1/eventing-mtchannel-broker-rhel8@sha256:f2aa320741980be3126af4f6553fbcfb81388eef43bf2d00ef951d6cc9a48368 |
openshift-serverless-1/eventing-mtping-rhel8@sha256:978409df9967a25e03547163aade8d6a905da3ec00c036e59ef5113880934324 |
openshift-serverless-1/eventing-storage-version-migration-rhel8@sha256:a1019681894da568e578a2a716c933e4400502a7a8686f963e5412ec5f1ddd06 |
openshift-serverless-1/eventing-webhook-rhel8@sha256:6509660ca03c1fc49ddc2d160d64da9b75286f99d5b61f5ed51dc39d74ce4452 |
openshift-serverless-1/func-utils-rhel8@sha256:1885cd5d972e8d384b075954b0cf274794df8c3937266f3a8dbc837989c59e6f |
openshift-serverless-1/ingress-rhel8-operator@sha256:8b9859a049ae2c7d8428a87f38e4f77b3c5f6fd25c0400379200448a14b60bbb |
openshift-serverless-1/kn-cli-artifacts-rhel8@sha256:4d019bbf7d3e6c86d167e6efe72477f14b47e0966deb759d0e4780054e619e01 |
openshift-serverless-1/knative-rhel8-operator@sha256:1bc2c297bc18d46e58c3edbfaff7804123e687d7b485b84f2243c27a335b76f1 |
openshift-serverless-1/kourier-control-rhel8@sha256:497e39a7738930b5bcb02a3bf59098b600b4a3dafc3d3bb757ca4826ed54b32d |
openshift-serverless-1/net-istio-controller-rhel8@sha256:f3b2625e3825159cad4d2ca9efb75a3e256ad607d61fd52c10295a15b4705e49 |
openshift-serverless-1/net-istio-webhook-rhel8@sha256:c25784b825fb3728cc199fd7da1ef584100d8a219fdb36d09e2e239a491e41c7 |
openshift-serverless-1/serverless-rhel8-operator@sha256:724a188cd5793d98abea61b6b2d440d8285416b66c4100d86ee3cd85cb9c91e5 |
openshift-serverless-1/serving-activator-rhel8@sha256:2713dee079c28633c47e21d4ffad870a396b3ba88ccec84c581fa95d15d0cab5 |
openshift-serverless-1/serving-autoscaler-hpa-rhel8@sha256:b4d5ffd0bef1f591263c47fe8aafa454b67f929af44caa515c3e7cd2a854622a |
openshift-serverless-1/serving-autoscaler-rhel8@sha256:26d1caa9b552f8c715e739b1350108d8c6ebd0ad759aede641f4ef601d962c85 |
openshift-serverless-1/serving-controller-rhel8@sha256:0d9ce8676310e9d9774dc366e5cbcaf416042de762fbc124a6c0b99d85503e83 |
openshift-serverless-1/serving-domain-mapping-rhel8@sha256:9639e560bd542e29b742ef41a37d3353a9d872d16b2a64477af5c0d59e6d73e8 |
openshift-serverless-1/serving-domain-mapping-webhook-rhel8@sha256:8c9ad2b89febbc53eb3577fdd670f506a174937cfb87d0b009f68f995e14102b |
openshift-serverless-1/serving-queue-rhel8@sha256:b9d0817b6df0be914bd9b505bd87c6f800dcca2697995c4d5e76d49da8635551 |
openshift-serverless-1/serving-storage-version-migration-rhel8@sha256:74a37086a0fb0f20e61ea0fbc85d57eb65a6b8801f1da4ed7c801d6ed10f6e6e |
openshift-serverless-1/serving-webhook-rhel8@sha256:0db7a3703df08fcd6d4ae8629f2b0aa3534f18c365d713e939f3af238e01b1ff |
openshift-serverless-1/svls-must-gather-rhel8@sha256:d6503aef9375f65d2675611489ecd20fc6f861031da5bdb813c098c4a69849e6 |
x86_64
openshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8@sha256:2d70c6b6320ba66ff8fda1662f2e83441e73aafcaf56e70ba6fb3c0d2c8d4e80 |
openshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8@sha256:09838c771be11fe7cb72d789ad87ca6c8ad7f2e5b33ee5a0208e9f0222334aea |
openshift-serverless-1/client-kn-rhel8@sha256:95604b77787df961e589bf93fb7e565140ca985cc02ff9d6c90fc7f15a0eaab3 |
openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8@sha256:20b559d9a8c41993f0d02d5348893eebb02f3d174a59a1bd017e2975822ff619 |
openshift-serverless-1/eventing-controller-rhel8@sha256:da4513526b2c3bf689bfdae0c65f7c493a8ddf4dc6ef5d8f6ced723af931c938 |
openshift-serverless-1/eventing-in-memory-channel-controller-rhel8@sha256:1222ecb0e6622666cd22a456160b83861e12a0f2edeee9385c1aa2edc761f1de |
openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8@sha256:82cb08a20f724143ee09c634776317e16a0d7863200f75bc6bb900447c3feb18 |
openshift-serverless-1/eventing-kafka-broker-controller-rhel8@sha256:86d11f76f0c83c037b7cc0fc519d1c25af3357653bfcee1678e960b99300b476 |
openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8@sha256:021b8b11162a10473dfa6494e40566d5c18c6666de1f75f47621e118d207b371 |
openshift-serverless-1/eventing-kafka-broker-post-install-rhel8@sha256:125025ff839149248cc51c34359f0bcd3d18137bcf8adcd66b4dacfe0547de92 |
openshift-serverless-1/eventing-kafka-broker-receiver-rhel8@sha256:c467bb15c2d9f640e77443e053c584d9e29c4023b91221e5b54d991ace28afb9 |
openshift-serverless-1/eventing-kafka-broker-webhook-rhel8@sha256:651cbcb60f4aa1c47fadfcc73819c75632c59e606d8b797762b3463961d58c9b |
openshift-serverless-1/eventing-mtbroker-filter-rhel8@sha256:72caab617bd179f1802a89816b155a207ddf17c58157ae87b6686fab9b2bae5f |
openshift-serverless-1/eventing-mtbroker-ingress-rhel8@sha256:b9747b6693c418af250b5093329a5f9d8972fcd97ba6b4cdf8004a73ef6d5769 |
openshift-serverless-1/eventing-mtchannel-broker-rhel8@sha256:e2ca422034ba5914d25f7d08ea5fedef7ea0a7e3ff8fca76ec8cc12b8e948c31 |
openshift-serverless-1/eventing-mtping-rhel8@sha256:0e7da0ea7aefba3d1e2ff084ca2ac8f63922f2295975a1695fe2a901682f4de8 |
openshift-serverless-1/eventing-storage-version-migration-rhel8@sha256:f86576956c87dc49590c6bd7e8b2ff84ada528fb849dbc3b0f6a93b49aa5df64 |
openshift-serverless-1/eventing-webhook-rhel8@sha256:6271ac3cb7b7c5d833d42f653d99ab657bfd1cfac9ac1b88f03f85184ec5f3a8 |
openshift-serverless-1/func-utils-rhel8@sha256:9141bded47062588d7fd43efa193bcfec53bac14551c3e4ea9b44a8557fbc754 |
openshift-serverless-1/ingress-rhel8-operator@sha256:77cd2c94ff900001186ada4f0b06f1796601351cfdb5b82014bcb203e31b3051 |
openshift-serverless-1/kn-cli-artifacts-rhel8@sha256:76afd3498f6ae481b19bc67c8045bd939635bc3461c871b3c9581114ac6404bd |
openshift-serverless-1/knative-rhel8-operator@sha256:91f446d198aaa3c68268c03f55696ffe7f21c5505ebe790cf9f8b18eaebc7412 |
openshift-serverless-1/kourier-control-rhel8@sha256:ec834b6739c66fe64f66de5ae35e620417481d59f122c9466f41678ab9282a8b |
openshift-serverless-1/net-istio-controller-rhel8@sha256:fb952974ed8689187cc6d4e7bee37b1cc949a1ca4a9e045f3d5d37dcb0ab2d20 |
openshift-serverless-1/net-istio-webhook-rhel8@sha256:e8bd2ae5178f9d16a0f4679573cbce8b73afe7263c6f4939a1012331e41cbc01 |
openshift-serverless-1/serverless-operator-bundle@sha256:12373623440b5b1aaea228550674ee69fe926ac6f12e7adffb5592afe1b98fca |
openshift-serverless-1/serverless-rhel8-operator@sha256:109ede85a0b8352f60826768e69a862f12bf568a4396b8041e6bd89b4c321ec1 |
openshift-serverless-1/serving-activator-rhel8@sha256:1072e7afb262f5d44e9feecdce9e305d46de3447a2e082ccc44bd42870143a54 |
openshift-serverless-1/serving-autoscaler-hpa-rhel8@sha256:319ab2387ca560faac48b05d480625e2bc32d9dfdf75e7cc4207c4437b51a9c5 |
openshift-serverless-1/serving-autoscaler-rhel8@sha256:1e8b69aa5d88d4c7313261fa54697e4510131cc387632141aebe3ee3a6d2460e |
openshift-serverless-1/serving-controller-rhel8@sha256:546bfe7edf8b0f83c6502130a00dfb32765386703accae4415dabc0d8ac888ec |
openshift-serverless-1/serving-domain-mapping-rhel8@sha256:de3573d243d7027101896f7c2e0b3f9e56a61879a252eb5e620b56308eabcb71 |
openshift-serverless-1/serving-domain-mapping-webhook-rhel8@sha256:eb69a34a0661054436385da1b6a270c645d5b7a652bd31b450283cc1e16d9019 |
openshift-serverless-1/serving-queue-rhel8@sha256:0c82cf0912a9a8a555a2dd7668a8b14132d368025644d1ed891001ff6088562f |
openshift-serverless-1/serving-storage-version-migration-rhel8@sha256:58daa415a9393f13a7708bc17d4cd39ce3f5a20de93ad16ac28d6513b9bfb80a |
openshift-serverless-1/serving-webhook-rhel8@sha256:aca371110b2e07088d3ae6606e01baf503ee333907c2a4ddb5f919860b70c8e3 |
openshift-serverless-1/svls-must-gather-rhel8@sha256:8ab39d48f9e5ab2ebcd0e554c63ec9771066c3e01dd9ea0a0f56186a48e3db23 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.