RHSA-2020:3372MediumCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3scale-istio-adapter-rhel8-container security update

Published
August 6, 2020
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2020-9283 — golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash

🎯 Affected products2

  • OpenShift Service Mesh 1.0
  • openshift-service-mesh/3scale-istio-adapter-rhel8@sha256:fcae2ea5da6d94016b2502f277b1a7fd3e29d0357fc727fcd61963026d22e607_amd64 as a component of OpenShift Service Mesh 1.0

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (6)