Uploaded image for project: 'Red Hat OpenShift Data Science'
  1. Red Hat OpenShift Data Science
  2. RHODS-12860

CVE-2023-44487 DOS affecting operator-lifecycle-manager-server package, versions <0.26.0

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None

      Description of problem: 

      Affected versions of this package are vulnerable to Denial of Service (DoS) in the implementation of the HTTP/2 protocol, Affecting github.com/operator-framework/operator-lifecycle-manager/pkg/package-server/server package, versions <0.26.0

      Prerequisites (if any, like setup, operators/versions):

      Steps to Reproduce

      1. <steps>

      Actual results:

      Expected results:

      Reproducibility (Always/Intermittent/Only Once):

      Build Details:

      Fix : Upgrade github.com/operator-framework/operator-lifecycle-manager/pkg/package-server/server to version 0.26.0 or higher.

      Additional info: https://github.com/operator-framework/operator-lifecycle-manager/releases/tag/v0.25.0 

            rh-ee-wenzhou Wen Zhou
            miram Mohammadi Iram
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: