-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.0102
          OpenShift Serverless 1.9.0 release and security update
                              12 January 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           OpenShift Serverless 1.9.0
Publisher:         Red Hat
Operating System:  Red Hat
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-16845 CVE-2020-15586 

Reference:         ESB-2020.4137
                   ESB-2020.4136
                   ESB-2020.3073

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2021:0072

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: OpenShift Serverless 1.9.0 release and security update
Advisory ID:       RHSA-2021:0072-01
Product:           Red Hat OpenShift Serverless
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:0072
Issue date:        2021-01-11
CVE Names:         CVE-2020-15586 CVE-2020-16845 
=====================================================================

1. Summary:

OpenShift Serverless 1.9.0 release and security update is now available.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Serverless 1.9.0 is a generally available release of the
OpenShift Serverless Operator. This version of the OpenShift Serverless
Operator is supported on Red Hat OpenShift Container Platform version 4.5.

Security Fix(es):

* golang: data race in certain net/http servers including ReverseProxy can
lead to DoS (CVE-2020-15586)

* golang: ReadUvarint and ReadVarint can read an unlimited number of bytes
from invalid inputs (CVE-2020-16845)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

See the documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/
4.5/html/serverless_applications/index

4. Bugs fixed (https://bugzilla.redhat.com/):

1856953 - CVE-2020-15586 golang: data race in certain net/http servers including ReverseProxy can lead to DoS
1867099 - CVE-2020-16845 golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs

5. References:

https://access.redhat.com/security/cve/CVE-2020-15586
https://access.redhat.com/security/cve/CVE-2020-16845
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.5/html/serverless_applications/index

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBX/zKctzjgjWX9erEAQiWdw//ZDcgNOeTEo8Qo9Ps1OEURERmOuGsmVjF
/wrM57GkSZWPkY5bsqklCr80qZNrgno4XAR+naAdu0fKAmk3ZvEEqHeuuU+J1ecy
VWFoilvW6+GCx84Fy2vES/1ZlxMEHJ2v0LtUYFsamtaKcusxUMK0WRlxEOp5jwVB
TC+2MOHyj3XA42OdvOpHqMo30OBCBkef6dntuf0/Gx1yw3p2I1wR7zv+xnvAeNBe
+6FYx1A7CXVJxc3xDl7+sNdhjFhB8rw7frzX+1GLcAkPcCKp7GSScr8NEPURhov7
OxPthEy63E3/VFvtxevCzuPSy+37l6ijoB0RPgeTQI4F/SeYWOVLg8NX+X8l0tf3
a6lCDk5do8KHJIxbAqg/lCeOcn2A7ThoiWsbrwLoG9t3fNJFVBD0Zm4AS1lEVhzy
4dIAzf+AAkrUZbWWzJkp4mR3NnCFZ2MW7o2EtD5vt+9vIH8oYyoKl1XBiygW9onC
u9BGCgBM50RclO0Qm6UuWU/79COY4j9V0JEuVObC3IwWgFZtF+5+3eDsvyXif0I2
HEHLrl/W00hqm4ab4DkT7WxCOq1DnOjUwUW7YFzjjJXcuaJuuNNYASBujoDID2Il
aW/waHs/xlsqc5ULwuZ9dQ4xtoW4/CiEOYBNiSji0LHmcGaSUocMYix6BlK+NeNA
NIakorHKBlU=
=Hu+l
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBX/0T+ONLKJtyKPYoAQg75w/8DDQGwNdCssLOU372T3HP0MtD//aXYWtY
OV9REGrJCdAzwmHAxSs5mjrRbHxzIbI6WnfkWlPH3wA1a5p3vwHbTgZGHQjYVrOD
53jDdU6tiCjHAE+eY4/tqX2k8ue5MgXy4Nmuqhks0YNGOzToEeSaXI/RvTqZBNw5
8kBL9A5tpVwo9M8Ie26fxpnTnjkxXtw1OfRp3n3pYFERZQjwLjoR4b0F8cHODnh8
L06OFBoI71/+41kPxVQP99njXhuV8N9C03Xw73pzyWtI/wIYLs74DlKTngJJ1z5j
nk9a4+vyaH2Am+3vnKL3YhWQiYmaCgy97iIgDz71On/NsmzHgnXMCEA8s6qrEisq
/R2OZ20oYEL4o6stRECqEUPWd0q0+vMhCl4jGJWlQzd3LQg7ibMjchg1Sno8Wq7+
hU3f6cLzM9GhxgRyakrJHR7j5wPjGiDJDugqH7AyTJ+mMnFX8ZJSOQeDMgU83R+o
VEEXQrb1B00VH9W3iBJP5eUSa166vVQHuiSb8FsymmrOsfwxPDJ6fdQ918yPLukq
QICZciWEdL+M/9XzIExbxkJXcDD1gOC6k45yCcXpfVlnx/U321G00eflajQwtlPi
ec2Ac40dI7eYg4b58PLdeiV9gmZdd3zuVIbblKKZpkPMB3JcfdOjtiZUr3xYgsXi
ZlomXePxDOY=
=m5DJ
-----END PGP SIGNATURE-----