RHSA-2022:1739MediumCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.2.1 containers security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-44906 — minimist: prototype pollution
CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor
CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak
CVE-2022-24771 — node-forge: Signature verification leniency in checking digestAlgorithm structure can lead to signature forgery
CVE-2022-24772 — node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery
CVE-2022-24773 — node-forge: Signature verification leniency in checking DigestInfo structure
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2022:1739
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067461
- externalhttps://issues.redhat.com/browse/OSSM-1435
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1739.json