RHSA-2020:3370LowCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Jaeger 1.17.6 container images security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-8203 — nodejs-lodash: prototype pollution in zipObjectDeep function CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
🎯 Affected products9
- Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-agent-rhel7@sha256:abad0b25b8d40fae71970c581029afc128d9a8ab2439d560d0b715c3ec287e14_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-all-in-one-rhel7@sha256:2e3f471079a34e9c497045a4c1f805c648cac28bd550b91471c7fb6c7d7b9774_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-collector-rhel7@sha256:5acdc905cdf19b06463eca5f7a3e9260e8618c644bbc43e925f003296cb7bdf6_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-es-index-cleaner-rhel7@sha256:8f0893cad468eaae61081b5b9d78fe512877bb1e1922dd5fff00df45731b79a2_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-es-rollover-rhel7@sha256:a2c413202eb52d172dc15722c20cc0e29ae5276f0ba1eefd1d62f05c2b86915b_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-ingester-rhel7@sha256:66f850d0de9ab915e5b9683fc6e82a3426df41b8c308972e81fefae00eb3a8d9_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-query-rhel7@sha256:2fe0840c5c88f0c7f01415e5661d8a32450a827cac555f93accf779d0ededb29_amd64 as a component of Red Hat OpenShift Jaeger 1.17
- distributed-tracing/jaeger-rhel7-operator@sha256:e561e5ad5940ecaac80ec803843329166b44dcf27d713e6259114a01d61b66f5_amd64 as a component of Red Hat OpenShift Jaeger 1.17
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://docs.openshift.com/container-platform/4.5/jaeger/jaeger_install/rhbjaeger-updating.html
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:3370
- externalhttps://access.redhat.com/security/updates/classification/#low
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857412
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3370.json