The vendor explicitly identifies these products as affected by this CVE.
- jenkins-operator-container as a component of OpenShift Developer Tools and Services
- jaeger as a component of OpenShift Service Mesh 1
- jaeger-operator as a component of OpenShift Service Mesh 1
- jaeger-operator.src as a component of OpenShift Service Mesh 1
- jaeger.src as a component of OpenShift Service Mesh 1
- cert-manager.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- cert-policy-controller.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- config-policy-controller.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- configmap-watcher.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- governance-policy-propagator.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- governance-policy-spec-sync.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- governance-policy-status-sync.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vulnerability. If an attacker is able to supply specific characters or strings to the vulnerable application, there is the potential to cause an infinite loop to occur using more memory, resulting in a denial of service.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
