Описание
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
A flaw was found in the math/big package of Go's standard library that causes a denial of service. Applications written in Go that use math/big via cryptographic packages, including crypto/rsa and crypto/x509, are vulnerable and can potentially cause panic via a crafted certificate chain. The highest threat from this vulnerability is to system availability.
Отчет
OpenShift ServiceMesh (OSSM) 1.1 is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities because it is now in the Maintenance Phase of the support. Openshift Virtualization 1 (formerly Container Native Virtualization) is Out Of Support Scope (OOSS) for Moderate and Low impact vulnerabilities. Red Hat Gluster Storage 3 shipped multi-cloud-object-gateway-cli and noobaa-operator container as a technical preview and is not currently planned to be addressed in future updates. OpenShift Container Platform (OCP) 4.5 and earlier are built with Go versions earlier than 1.14, which are not affected by this vulnerability. OCP 4.6 is built with Go 1.15 and is affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-agent-rhel7 | Not affected | ||
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-all-in-one-rhel7 | Not affected | ||
| Distributed Tracing Jaeger 1 | distributed-tracing/jaeger-rhel7-operator | Not affected | ||
| OpenShift Serverless | knative-serving | Affected | ||
| OpenShift Service Mesh 1 | ior | Out of support scope | ||
| OpenShift Service Mesh 1 | kiali | Out of support scope | ||
| OpenShift Service Mesh 1 | servicemesh | Out of support scope | ||
| OpenShift Service Mesh 1 | servicemesh-cni | Out of support scope | ||
| OpenShift Service Mesh 1 | servicemesh-grafana | Out of support scope | ||
| OpenShift Service Mesh 1 | servicemesh-operator | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.
EPSS
7.5 High
CVSS3