RHSA-2023:1326HighCVSS 7.8

Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update

Published
May 17, 2023
Last Modified
May 29, 2026

🔗 CVE IDs covered (24)

📋 Description

CVE-2021-4235 — go-yaml: Denial of Service in go-yaml CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2022-23525 — helm: Denial of service through through repository index file CVE-2022-23526 — helm: Denial of service through schema file CVE-2022-27191 — golang: crash in a golang.org/x/crypto/ssh server CVE-2022-41316 — vault: insufficient certificate revocation list checking CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-41721 — x/net/http2/h2c: request smuggling CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2022-41724 — golang: crypto/tls: large handshake records may cause panics CVE-2022-41725 — golang: net/http, mime/multipart: denial of service from excessive resource consumption CVE-2022-46146 — exporter-toolkit: authentication bypass via cache poisoning CVE-2023-0620 — vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File CVE-2023-0665 — hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata CVE-2023-25000 — hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations CVE-2023-25165 — helm: getHostByName Function Information Disclosure CVE-2023-25173 — containerd: Supplementary groups are not set up properly CVE-2023-25809 — runc: Rootless runc makes /sys/fs/cgroup writable CVE-2023-27561 — runc: volume mount race condition (regression of CVE-2019-19921) CVE-2023-28642 — runc: AppArmor can be bypassed when /proc inside the container is symlinked with a specific mount configuration CVE-2023-30841 — baremetal-operator: plain-text username and hashed password readable by anyone having a cluster-wide read-access

🔗 References (911)