The vendor explicitly identifies these products as affected by this CVE.
- cli as a component of OpenShift Serverless
- knative-eventing as a component of OpenShift Serverless
- servicemesh as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0
- servicemesh-istioctl as a component of OpenShift Service Mesh 2.0
- servicemesh-mixc as a component of OpenShift Service Mesh 2.0
- servicemesh-mixs as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-agent as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-discovery as a component of OpenShift Service Mesh 2.0
- servicemesh.src as a component of OpenShift Service Mesh 2.0
- Summary
- A vulnerability was found in archive/zip of the Go standard library. Applications written in Go where Reader.Open (the API implementing io/fs.FS introduced in Go 1.16) can panic when parsing a crafted ZIP archive containing completely invalid names or an empty filename argument.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
