Red Hat Security Advisory: Red Hat OpenShift Service Mesh security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2020-8203 — nodejs-lodash: prototype pollution in zipObjectDeep function CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic CVE-2020-11023 — jquery: Untrusted code execution via tag in HTML passed to DOM manipulation methods CVE-2020-12666 — macaron: open redirect in the static handler CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
🎯 Affected products25
- OpenShift Service Mesh 1.1
- Red Hat OpenShift Service Mesh 1.1
- ior-0:1.1.6-1.el8.src as a component of OpenShift Service Mesh 1.1
- ior-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- kiali-0:v1.12.10.redhat2-1.el7.src as a component of Red Hat OpenShift Service Mesh 1.1
- kiali-0:v1.12.10.redhat2-1.el7.x86_64 as a component of Red Hat OpenShift Service Mesh 1.1
- servicemesh-0:1.1.6-1.el8.src as a component of OpenShift Service Mesh 1.1
- servicemesh-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-citadel-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-cni-0:1.1.6-1.el8.src as a component of OpenShift Service Mesh 1.1
- servicemesh-cni-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-galley-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-grafana-0:6.4.3-13.el8.src as a component of OpenShift Service Mesh 1.1
- servicemesh-grafana-0:6.4.3-13.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-grafana-prometheus-0:6.4.3-13.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-istioctl-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-mixc-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-mixs-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-operator-0:1.1.6-2.el8.src as a component of OpenShift Service Mesh 1.1
- servicemesh-operator-0:1.1.6-2.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-pilot-agent-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-pilot-discovery-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-prometheus-0:2.14.0-14.el8.src as a component of OpenShift Service Mesh 1.1
- servicemesh-prometheus-0:2.14.0-14.el8.x86_64 as a component of OpenShift Service Mesh 1.1
- servicemesh-sidecar-injector-0:1.1.6-1.el8.x86_64 as a component of OpenShift Service Mesh 1.1
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:3369
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850034
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1853652
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857412
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3369.json