-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.3979
      Release of OpenShift Serverless and Serverless Client kn 1.19.0
                             24 November 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Openshift serverless
                   Openshift serverless client
Publisher:         Red Hat
Operating System:  Red Hat
Impact/Access:     Denial of Service        -- Remote/Unauthenticated
                   Access Confidential Data -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-36221 CVE-2021-33938 CVE-2021-33930
                   CVE-2021-33929 CVE-2021-33928 CVE-2021-22947
                   CVE-2021-22946 CVE-2021-3733 

Reference:         ESB-2021.3941
                   ESB-2021.3934
                   ESB-2021.3878

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2021:4765
   https://access.redhat.com/errata/RHSA-2021:4766

Comment: This bulletin contains two (2) Red Hat security advisories.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: Release of OpenShift Serverless Client kn 1.19.0
Advisory ID:       RHSA-2021:4765-01
Product:           Red Hat OpenShift Serverless
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:4765
Issue date:        2021-11-23
CVE Names:         CVE-2021-36221 
=====================================================================

1. Summary:

Release of OpenShift Serverless Client kn 1.19.0

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Openshift Serverless 1 on RHEL 8Base - ppc64le, s390x, x86_64

3. Description:

Red Hat OpenShift Serverless Client kn 1.19.0 provides a CLI to interact
with Red Hat OpenShift Serverless 1.19.0. The kn CLI is delivered as an RPM
package for installation on RHEL platforms, and as binaries for non-Linux
platforms.

Security Fix(es):

* golang: net/http/httputil: panic due to racy read of persistConn after
handler panic (CVE-2021-36221)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

See the Red Hat OpenShift Container Platform 4.6 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index
See the Red Hat OpenShift Container Platform 4.7 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index
See the Red Hat OpenShift Container Platform 4.8 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.8/html/serverless/index
See the Red Hat OpenShift Container Platform 4.9 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.9/html/serverless/index

5. Bugs fixed (https://bugzilla.redhat.com/):

1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic
2016255 - Release of Openshift Serverless Client 1.19.0

6. Package List:

Openshift Serverless 1 on RHEL 8Base:

Source:
openshift-serverless-clients-0.25.1-1.el8.src.rpm

ppc64le:
openshift-serverless-clients-0.25.1-1.el8.ppc64le.rpm

s390x:
openshift-serverless-clients-0.25.1-1.el8.s390x.rpm

x86_64:
openshift-serverless-clients-0.25.1-1.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2021-36221
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.8/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.9/html/serverless/index

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYZz9oNzjgjWX9erEAQhjew/9EeAac0uiyEFP58IN3qHHpbt0x3iv2Sc8
dI5/d9sh1KZ9H7VEm00eSnDkeCofUzP7cseTAOcpk5cQ/22hO3yfDZqnZE6ORNYw
VwVreCFcsMfDhnEPsanEaT1395dH8o3uFqx9o9C+qedhJFabfYNN7CVtVRW1H6xg
NOqAhjv56YJh9bLkdytwzOsDfb7eU8WLoNusqKZCVJixFbBdTSMkyCAETVyDhl8p
8dSUDNHIhK+o7QwUScPzrAH5jiT4VKQgZVaVAH4NDtcYHaoG2pcdqCHIuTY49N7R
ZZo3mEZBxaeuZXchJ2CxGPLqanOXn78TdILVHbZ5inbXaZ9aMDjfzEZkVRCNssBW
d7Nxl5bRAqzgNwjbrKHls2ssBxe1F8X6t/5yOtBdZGVmDgXZGSl2/U2yaO9kA2Qv
7GRagWTKJAv9APoaj2ILarUO+Gf410G4Cpc0OEN45Glp7tqW/PpI65B4fEZGnhFH
37kLzeTHm+aOpLcxyCc3I3uVrTtD23mf7vwUj3O8AURQRng8WwymWxOuza7Eo2iz
rX46zJF9TOxeGcHJ3Ykl9BDR3gQh6pQ9ccTjFFz0vrev8X7YHbhUvDDgGmK/5xya
voswqaVuwD37RjzmF7t65PC+XOyt9A++Vo2/XfbUfkRLIgytx+UkQa7CjGDd8nvu
/YGicfc9BgQ=
=TWiE
- -----END PGP SIGNATURE-----

- ---------------------------------------------------------------------------------------------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Moderate: Release of OpenShift Serverless 1.19.0
Advisory ID:       RHSA-2021:4766-01
Product:           Red Hat OpenShift Serverless
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:4766
Issue date:        2021-11-23
CVE Names:         CVE-2021-3733 CVE-2021-22946 CVE-2021-22947 
                   CVE-2021-33928 CVE-2021-33929 CVE-2021-33930 
                   CVE-2021-33938 CVE-2021-36221 
=====================================================================

1. Summary:

Release of OpenShift Serverless 1.19.0

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Serverless release of the OpenShift Serverless Operator.
This version of the OpenShift Serverless Operator is supported on Red Hat
OpenShift Container Platform versions 4.6, 4.7, 4.8 and 4.9, and includes
security and bug fixes and enhancements. For more information, see the
documentation listed in the References section.

Security Fix(es):

* golang: net/http/httputil: panic due to racy read of persistConn after
handler panic (CVE-2021-36221)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

See the Red Hat OpenShift Container Platform 4.6 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index
See the Red Hat OpenShift Container Platform 4.7 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index
See the Red Hat OpenShift Container Platform 4.8 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.8/html/serverless/index
See the Red Hat OpenShift Container Platform 4.9 documentation at:
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.9/html/serverless/index

4. Bugs fixed (https://bugzilla.redhat.com/):

1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic
2016256 - Release of OpenShift Serverless Eventing 1.19.0
2016258 - Release of OpenShift Serverless Serving 1.19.0

5. References:

https://access.redhat.com/security/cve/CVE-2021-3733
https://access.redhat.com/security/cve/CVE-2021-22946
https://access.redhat.com/security/cve/CVE-2021-22947
https://access.redhat.com/security/cve/CVE-2021-33928
https://access.redhat.com/security/cve/CVE-2021-33929
https://access.redhat.com/security/cve/CVE-2021-33930
https://access.redhat.com/security/cve/CVE-2021-33938
https://access.redhat.com/security/cve/CVE-2021-36221
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.8/html/serverless/index
https://access.redhat.com/documentation/en-us/openshift_container_platform/4.9/html/serverless/index

6. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYZz9ndzjgjWX9erEAQjcxw//ThWLuR04rJhSDaIii743ZOuIzEXW2qlN
w9BzSoC5LzFMokZE2xLROmcz1cMfYjxU588REdP/1/42iSub7gt8+Defam00Uagw
Dm2SA5Je3mT/O44Cfzvg/YCnAlAiZKQA6XIx+whlfKtRphB+PvxV0Za15PPoiM/V
YEmV41DXlKkGlRLlOTmJ5ELn7mN4r8BmH3fg8Gp6pGtESOqSP5iW79vQzQBJdojK
pdDEJWjRc2bfCTcXIgR6lry2paSyECkL/3KTgNmMeLE+kRvhPL/fC1TGGIzkygKv
LN9ychyhRMfD1TFyIBYQmVRfTaoAvUaCa/zoGBRRZfyXG7q3ig4xBDNUiJtDU5KJ
pXnlIQcHwYCRkqxpyX1KlAaAIri6rUIsk3kOz+NBf51BQtwg8yprjZXdNWNgJrDU
gzEK0cZAII9/xD0DhBMcYJnmejZpqTnR1O/eaUHQpjyVi1mbekf4YPcz2hmbqUmp
5D4zOouBUxmBG4r7vnndvVEv059cVaglPxfv9YXHdf3o5hpcnzce1IDws2aS85HM
R0aVYDlzWTeZBgXBIcuoxuug2J+1TddQCik8NL0eV1GEXyB/cMUEUDmvlS0+tChy
cW0Lnq75vj5doRudAuBMOFIeJcNfHlXkXOcMRa9dRitnYjtP40tosW3Nbf2jKusT
VuCeUO89CXk=
=T3Li
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYZ2WtONLKJtyKPYoAQhf6w/+OzHVO4ZaYCA4guQjSJqAab+mRvGBPv56
RJhaC/vktDm/kf1aI7QvJ/57YIpmGGCC6j+XgD9ZyD53zCD/qF6lCoKvKgpGGcWc
hb3HamZxP9VeiaJTt6ITbTIs3F9rifsLzMe5NXgjbkOlX63U/hb7LCqsFJjHEPcr
1ERWklvZECi9y0jY/v7vcTGtaHsN7OV8LPpdz9NjWc5HYLhXgJAKy/5kPEF864JH
Qv9B/eaYiztdl3fvD17Ez/lbmL3LJ+xz6umQYf6WrvfUKTPG98OvsgX9gE9/gw0Y
wy6JWrXWorgmzZHUT1p6w47VOe06ttv4uHCFIHbrKpv9mechgiz+Jfny/dfg9IZP
ZW82/W7ysP4Hm2bLTdr9WFJKPGfwYAWmEwf82t3Mvi97EQ5b+g7zQx3qxU/YdFWY
9ipsgEX5ZlH7OHsHpQiD9VuNR0JdLG+Lqic+vb4D2A+txMveM9TrqeWU55kwOL3P
B8eWjHBrHwNgFi0Vu4RmRkCfw1VOGjpVJ54dbjMs7l2Xlj3NBnqf6xElNAA4eXG8
0imP42XkIXKgFgIrUQbtCwLBCfi1HWvAqL+5nl1VDsLCg+5+jYDV+4Ts5psogd7V
6QDUivH5nGsyxQz0O/dekZiQBoVkLOmRjyJ3TvMPa/hfzHarhhqUWat8+yzk5j5M
q65zhfpQ2Ng=
=uePo
-----END PGP SIGNATURE-----