Hide Forgot
An integer overflow vulnerability exists with the length of frames received via a websocket connections. An attacker would use this flaw to cause a denial of service attack on a HTTP Server serving websocket connections.
Upstream Commit: https://github.com/gorilla/websocket/commit/5b740c29263eb386f33f265561c8262522f19d37
External References: https://github.com/gorilla/websocket/security/advisories/GHSA-jf24-p9p9-4rjh
This issue has been addressed in the following products: RHEL-8-CNV-2.5 RHEL-7-CNV-2.5 Via RHSA-2021:0187 https://access.redhat.com/errata/RHSA-2021:0187
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2021:0190 https://access.redhat.com/errata/RHSA-2021:0190
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-27813
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2020:5633 https://access.redhat.com/errata/RHSA-2020:5633
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2020:5364 https://access.redhat.com/errata/RHSA-2020:5364
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2021:0100 https://access.redhat.com/errata/RHSA-2021:0100
This issue has been addressed in the following products: RHEL-8-CNV-2.6 Via RHSA-2021:0799 https://access.redhat.com/errata/RHSA-2021:0799
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2021:0833 https://access.redhat.com/errata/RHSA-2021:0833
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2021:1561 https://access.redhat.com/errata/RHSA-2021:1561
This issue has been addressed in the following products: RHEL-8-CNV-4.8 Via RHSA-2021:2920 https://access.redhat.com/errata/RHSA-2021:2920