VDB
RHSA-2023%3A0692
RHSA-2023%3A0692
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was found in the golang.org/x/text/language package. An attacker can craft an Accept-Language header which ParseAcceptLanguage will take significant time to parse. This issue leads to a denial of service, and can impact availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:1792552893fe7f146f04033f342e9095f0068dd60e1f3a1e2dad9c5111dd28e6_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:1792552893fe7f146f04033f342e9095f0068dd60e1f3a1e2dad9c5111dd28e6_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:82ebe14f59b19d628ecbe63a212ecaf4623a98a432b8b4525b118c6b24c87d90_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-mustgather-rhel8@sha256:f269ee31bf0eb544ccabb2d72d807dc5d6587186d76bb020a00fac20221c7b0f_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-mustgather-rhel8@sha256:f269ee31bf0eb544ccabb2d72d807dc5d6587186d76bb020a00fac20221c7b0f_amd64 |
| Red Hat | oadp/oadp-rhel8-operator@sha256:4d983585501df88bd5f602010cb72ea460982b25fa91c05a83f0b711a457661a_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-rhel8-operator@sha256:4d983585501df88bd5f602010cb72ea460982b25fa91c05a83f0b711a457661a_amd64 |
| Red Hat | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:aed05c3b1e7eee9054ee45b499e2eb31a534979468ba22be46f83459d0dab4ae_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-csi-rhel8@sha256:aed05c3b1e7eee9054ee45b499e2eb31a534979468ba22be46f83459d0dab4ae_amd64 |
| Red Hat | oadp/oadp-operator-bundle@sha256:d0927b9f279ad60a073773ec624dc66db000b3d0b727254fbadb6af3a3c7b646_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-operator-bundle@sha256:d0927b9f279ad60a073773ec624dc66db000b3d0b727254fbadb6af3a3c7b646_amd64 |
| Red Hat | oadp/oadp-rhel8-operator@sha256:4d983585501df88bd5f602010cb72ea460982b25fa91c05a83f0b711a457661a_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-rhel8-operator@sha256:4d983585501df88bd5f602010cb72ea460982b25fa91c05a83f0b711a457661a_amd64 |
| Red Hat | oadp/oadp-velero-plugin-rhel8@sha256:d9a46e3da52db4880cde8faa6f5e406039e6f38585dd14dc97db4b5846b4f7e5_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-velero-plugin-for-aws-rhel8@sha256:1792552893fe7f146f04033f342e9095f0068dd60e1f3a1e2dad9c5111dd28e6_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:3749d7386635cf598147d5021584672ab26761b9dca52ca05b179d47557ac549_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:3749d7386635cf598147d5021584672ab26761b9dca52ca05b179d47557ac549_amd64 |
| Red Hat | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:3749d7386635cf598147d5021584672ab26761b9dca52ca05b179d47557ac549_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-kubevirt-velero-plugin-rhel8@sha256:3749d7386635cf598147d5021584672ab26761b9dca52ca05b179d47557ac549_amd64 |
| Red Hat | oadp/oadp-velero-plugin-rhel8@sha256:d9a46e3da52db4880cde8faa6f5e406039e6f38585dd14dc97db4b5846b4f7e5_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-rhel8@sha256:d9a46e3da52db4880cde8faa6f5e406039e6f38585dd14dc97db4b5846b4f7e5_amd64 |
| Red Hat | oadp/oadp-velero-rhel8@sha256:a5973be01956a09f75bcd65481d484c12fd7bcefad5b852fd0567f6d8b51f0be_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:82ebe14f59b19d628ecbe63a212ecaf4623a98a432b8b4525b118c6b24c87d90_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-plugin-for-gcp-rhel8@sha256:82ebe14f59b19d628ecbe63a212ecaf4623a98a432b8b4525b118c6b24c87d90_amd64 |
| Red Hat | oadp/oadp-operator-bundle@sha256:d0927b9f279ad60a073773ec624dc66db000b3d0b727254fbadb6af3a3c7b646_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-operator-bundle@sha256:d0927b9f279ad60a073773ec624dc66db000b3d0b727254fbadb6af3a3c7b646_amd64 |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:9fda0732f74519e71a4f10f10b32a451f01c3bf9eae37f7bd1ff90ad8baf3a9f_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:9fda0732f74519e71a4f10f10b32a451f01c3bf9eae37f7bd1ff90ad8baf3a9f_amd64 |
| Red Hat | oadp/oadp-registry-rhel8@sha256:ea215cbf22a37c2f2b77c9901dc5c7493f1f3a694276f42d11fcefbf045a8b38_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-registry-rhel8@sha256:ea215cbf22a37c2f2b77c9901dc5c7493f1f3a694276f42d11fcefbf045a8b38_amd64 |
| Red Hat | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:9fda0732f74519e71a4f10f10b32a451f01c3bf9eae37f7bd1ff90ad8baf3a9f_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-velero-restic-restore-helper-rhel8@sha256:9fda0732f74519e71a4f10f10b32a451f01c3bf9eae37f7bd1ff90ad8baf3a9f_amd64 |
| Red Hat | oadp/oadp-velero-rhel8@sha256:a5973be01956a09f75bcd65481d484c12fd7bcefad5b852fd0567f6d8b51f0be_amd64 as a component of 8Base-OADP-1.0 | * |
| Red Hat | oadp/oadp-registry-rhel8@sha256:ea215cbf22a37c2f2b77c9901dc5c7493f1f3a694276f42d11fcefbf045a8b38_amd64 as a component of 8Base-OADP-1.0 | oadp/oadp-registry-rhel8@sha256:ea215cbf22a37c2f2b77c9901dc5c7493f1f3a694276f42d11fcefbf045a8b38_amd64 |
…and 4 more
Timeline
- Feb 9, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:0692 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2134010 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2161274 issue
- https://issues.redhat.com/browse/MIG-1050 advisory
- https://issues.redhat.com/browse/OADP-1180 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0692.json advisory
- https://access.redhat.com/security/cve/CVE-2022-32149 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-32149 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-32149 advisory
- https://go.dev/issue/56152 advisory
- https://groups.google.com/g/golang-dev/c/qfPIly0X7aU advisory
- https://access.redhat.com/security/cve/CVE-2022-41717 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41717 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41717 advisory
- https://go.dev/cl/455635 advisory
- https://go.dev/cl/455717 advisory
- https://go.dev/issue/56350 advisory
- https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ advisory
- https://pkg.go.dev/vuln/GO-2022-1144 advisory