It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These will be fixed with next release.
*** Bug 1995394 has been marked as a duplicate of this bug. ***
*** Bug 1995395 has been marked as a duplicate of this bug. ***
*** Bug 1995396 has been marked as a duplicate of this bug. ***
Since only the Knative CLI build used an older version of Go that did not have the CVE fix, marking knative-serving and knative-eventing as not affected.
This issue has been addressed in the following products: Openshift Serverless 1 on RHEL 8 Via RHSA-2021:3555 https://access.redhat.com/errata/RHSA-2021:3555
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3703
This issue has been addressed in the following products: Openshift Serveless 1.17 Via RHSA-2021:3556 https://access.redhat.com/errata/RHSA-2021:3556