-
Bug
-
Resolution: Done-Errata
-
Undefined
-
None
-
None
-
None
-
None
-
False
-
None
-
False
-
Testable
-
No
-
No
-
No
-
Pending
-
None
-
-
Description of problem:
Affected versions of this package are vulnerable to Denial of Service (DoS) in the implementation of the HTTP/2 protocol, Affecting github.com/operator-framework/operator-lifecycle-manager/pkg/package-server/server package, versions <0.26.0
Prerequisites (if any, like setup, operators/versions):
Steps to Reproduce
- <steps>
Actual results:
Expected results:
Reproducibility (Always/Intermittent/Only Once):
Build Details:
Fix : Upgrade github.com/operator-framework/operator-lifecycle-manager/pkg/package-server/server to version 0.26.0 or higher.
Additional info: https://github.com/operator-framework/operator-lifecycle-manager/releases/tag/v0.25.0
- links to
-
RHBA-2023:122672 RHODS 2.4 - Red Hat OpenShift Data Science
- mentioned on