CVE-2022-32148

medium
Published 2022-08-01 Β· Modified 2023-05-16
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2023:2802: container-tools:4.0 security and bug fix update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Application Interconnect 1 for RHEL 8skupper-cli-0:1.0.2-2.el8RHSA-2022:61132022-08-18T00:00:00Z Logging subsystem for Red Hat OpenShift…

Description

golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working

CVSS v3: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Application Interconnect 1 for RHEL 8skupper-cli-0:1.0.2-2.el8RHSA-2022:61132022-08-18T00:00:00Z
Logging subsystem for Red Hat OpenShift 5.4openshift-logging/logging-loki-rhel8:v2.5.0-42RHSA-2022:61832022-09-06T00:00:00Z
Node Maintenance Operator 4.11 for RHEL 8workload-availability/node-maintenance-rhel8-operator:v4.11.1-1RHSA-2022:61882022-08-25T00:00:00Z
OADP-1.0-RHEL-8oadp/oadp-velero-rhel8:1.0.4-6RHSA-2022:64302022-09-13T00:00:00Z
OpenShift Custom Metrics Autoscaler 2custom-metrics-autoscaler-tech-preview/custom-metrics-autoscaler-rhel8:2.8.2-143RHSA-2023:10422023-03-06T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/client-kn-rhel8:1.3.1-4RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-controller-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-kafka-broker-controller-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-kafka-broker-post-install-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-kafka-broker-webhook-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-mtbroker-filter-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-mtbroker-ingress-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-mtchannel-broker-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-mtping-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-storage-version-migration-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-sugar-controller-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/eventing-webhook-rhel8:1.3.2-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/ingress-rhel8-operator:1.24.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/knative-rhel8-operator:1.24.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/kn-cli-artifacts-rhel8:1.3.1-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/kourier-control-rhel8:1.3.0-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/net-istio-controller-rhel8:1.3.0-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/net-istio-webhook-rhel8:1.3.0-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serverless-operator-bundle:1.24.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serverless-rhel8-operator:1.24.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-activator-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-autoscaler-hpa-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-autoscaler-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-controller-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-domain-mapping-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-domain-mapping-webhook-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-queue-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-storage-version-migration-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/serving-webhook-rhel8:1.3.0-3RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1/svls-must-gather-rhel8:1.24.0-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1-tech-preview/eventing-kafka-broker-controller-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1-tech-preview/eventing-kafka-broker-dispatcher-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1-tech-preview/eventing-kafka-broker-receiver-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serveless 1.24openshift-serverless-1-tech-preview/eventing-kafka-broker-webhook-rhel8:1.3.2-2RHSA-2022:60402022-08-10T00:00:00Z
Openshift Serverless 1 on RHEL 8openshift-serverless-clients-0:1.3.1-4.el8RHSA-2022:60422022-08-10T00:00:00Z
OSSO-1.1-RHEL-8openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8:v1.1-11RHSA-2022:61522022-09-01T00:00:00Z
Red Hat Ceph Storage 6.1rhceph/rhceph-6-dashboard-rhel9:6-75RHSA-2023:36422023-06-15T00:00:00Z
Red Hat Developer Toolsgo-toolset-1.17-golang-0:1.17.12-1.el7_9RHSA-2022:58662022-08-02T00:00:00Z
Red Hat Enterprise Linux 8go-toolset:rhel8-8060020220720230014.97d7f71fRHSA-2022:57752022-08-01T00:00:00Z
Red Hat Enterprise Linux 8git-lfs-0:2.13.3-3.el8_6RHSA-2022:71292022-10-25T00:00:00Z
Red Hat Enterprise Linux 8grafana-0:7.5.15-3.el8RHSA-2022:75192022-11-08T00:00:00Z
Red Hat Enterprise Linux 8container-tools:3.0-8070020220802115906.39077419RHSA-2022:75292022-11-08T00:00:00Z
Red Hat Enterprise Linux 8grafana-pcp-0:3.2.0-2.el8RHSA-2022:76482022-11-08T00:00:00Z
Red Hat Enterprise Linux 8container-tools:rhel8-8080020230321153727.0f77c1b7RHSA-2023:27582023-05-16T00:00:00Z
Red Hat Enterprise Linux 8container-tools:4.0-8080020230217080101.8108cfbcRHSA-2023:28022023-05-16T00:00:00Z
Red Hat Enterprise Linux 9golang-0:1.17.12-1.el9_0RHSA-2022:57992022-08-01T00:00:00Z
Red Hat Enterprise Linux 9grafana-0:7.5.15-3.el9RHSA-2022:80572022-11-15T00:00:00Z
Red Hat Enterprise Linux 9grafana-pcp-0:3.2.0-3.el9RHSA-2022:82502022-11-15T00:00:00Z
Red Hat Enterprise Linux 9git-lfs-0:3.2.0-1.el9RHSA-2023:23572023-05-09T00:00:00Z
Red Hat Migration Toolkit for Containers 1.7rhmtc/openshift-velero-plugin-rhel8:v1.7.6-5RHSA-2022:90472022-12-15T00:00:00Z
Red Hat OpenShift Container Platform 4.11cri-o-0:1.24.3-6.rhaos4.11.gitc4567c0.el8RHSA-2022:86262022-11-28T00:00:00Z

Package state

ProductPackageState
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-controller-rhel9Affected
Node Maintenance Operatorworkload-availability/node-maintenance-rhel8-operatorAffected
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Pipelinesopenshift-pipelines-clientWill not fix
Red Hat 3scale API Management Platform 23scale-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/work-rhel8Affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Affected
Red Hat Ansible Automation Platform 2openshift-clientsWill not fix
Red Hat Ansible Automation Platform 2receptorAffected
Red Hat Ceph Storage 3golangOut of support scope
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Enterprise Linux 8osbuild-composerWill not fix
Red Hat Enterprise Linux 9buildahWill not fix
Red Hat Enterprise Linux 9conmonNot affected
Red Hat Enterprise Linux 9go-toolsetAffected
Red Hat Enterprise Linux 9ignitionWill not fix
Red Hat Enterprise Linux 9osbuild-composerWill not fix
Red Hat Enterprise Linux 9podmanWill not fix
Red Hat Enterprise Linux 9skopeoWill not fix
Red Hat OpenShift Container Platform 4buildahAffected
Red Hat OpenShift Container Platform 4conmonNot affected
Red Hat OpenShift Container Platform 4openshiftNot affected
Red Hat OpenShift Container Platform 4openshift-clientsAffected
Red Hat OpenShift Container Platform 4openshift-golang-builder-containerAffected
Red Hat OpenShift Container Platform 4podmanNot affected
Red Hat OpenShift Container Platform 4skopeoNot affected
Red Hat Openshift Data Foundation 4mcgAffected
Red Hat Openshift Data Foundation 4odf4/cephcsi-rhel9Affected
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-agent-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/gitops-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-kamAffected
Red Hat OpenShift on AWSrosaAffected
Red Hat Quay 3quay/clair-rhel8Affected
Red Hat Software Collectionsrh-git227-git-lfsWill not fix
Red Hat Storage 3golangWill not fix
Red Hat Storage 3go-toolset-7-golangWill not fix
Red Hat Storage 3heketiOut of support scope
Red Hat Web Terminalweb-terminal-exec-containerFix deferred

Apply commands

bash fix
Apply RHSA-2022:6113 for Application Interconnect 1 for RHEL 8
yum update -y skupper-cli
# or:
dnf upgrade -y skupper-cli

Affected

VendorProductVersion
redhatMigration Toolkit for VirtualizationAffected
redhatNode Maintenance OperatorAffected
redhatOpenShift Developer Tools and ServicesAffected
redhatOpenShift Developer Tools and ServicesAffected
redhatRed Hat 3scale API Management Platform 2Affected
redhatRed Hat Advanced Cluster Management for Kubernetes 2Affected
redhatRed Hat Advanced Cluster Security 3Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ceph Storage 5Affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat OpenShift Container Platform 4Not affected
redhatRed Hat Openshift Data Foundation 4Affected
redhatRed Hat Openshift Data Foundation 4Affected
redhatRed Hat OpenShift distributed tracing 2Not affected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat OpenShift on AWSAffected
redhatRed Hat Quay 3Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 2 releases
VersionStatusFixed in
bullseye Affected β€”
bookworm Fixed 1.19~rc1-1
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed golang-src-1.17.12-1.el9_0.noarch.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
golang Gostdlib>=1.18.0-0,<1.18.41.17.12

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.