Lucene search

K
redhatRedHatRHSA-2022:6517
HistorySep 14, 2022 - 12:42 p.m.

(RHSA-2022:6517) Important: Release of containers for OSP 16.2.z director operator tech preview

2022-09-1412:42:43
access.redhat.com
40
rhsa-2022-6517
containers
osp 16.2.z
director
golang
compress/gzip
cve-2022-30631
security fix
containerd
cve-2021-41103
permissions

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.125

Percentile

95.5%

Release osp-director-operator images

Security Fix(es):

  • CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read [important]
  • CVE-2021-41103 golang: containerd: insufficiently restricted permissions on container root and plugin directories [medium]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.125

Percentile

95.5%