RHSA-2023:0264MediumCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift (Logging Subsystem) security update

Published
January 19, 2023
Last Modified
July 16, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2020-36518 — jackson-databind: denial of service via a large depth of nested objects CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-37601 — loader-utils: prototype pollution in function parseQuery in parseQuery.js CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2022-42003 — jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS CVE-2022-42004 — jackson-databind: use of deeply nested arrays

🔗 References (40)