RHSA-2022:1739MediumCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.2.1 containers security update

Published
May 5, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2021-44906 — minimist: prototype pollution CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2022-24771 — node-forge: Signature verification leniency in checking digestAlgorithm structure can lead to signature forgery CVE-2022-24772 — node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery CVE-2022-24773 — node-forge: Signature verification leniency in checking DigestInfo structure

🎯 Affected products10

  • OpenShift Service Mesh 2.1
  • openshift-service-mesh/istio-must-gather-rhel8@sha256:1b9dbbab044ab8e968d2759a11d703bd25cd9ea398f781810d8ee42f17bea6ae_ppc64le as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/istio-must-gather-rhel8@sha256:5474cbf94f487f1562ad768a229a73c103c853dc5dfa2efb3a3eb77729256bf9_amd64 as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/istio-must-gather-rhel8@sha256:cfa0361b9fe8e40a81fe5f1e278ad7a3598567e0ae80a84345ef0a520c1be8f4_s390x as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/kiali-rhel8-operator@sha256:278b369e56a3d9d15e06140446dcc25cd58279c001f81305c2cd4431a5d17901_s390x as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/kiali-rhel8-operator@sha256:bec742ce66c9d1c1bd484c404d3e80e11d72e118f990df3d24bbb0d66e04d498_amd64 as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/kiali-rhel8-operator@sha256:c39704bb84a8a070752c0eb4c507c4a73f2fb90eaf563ca8e48a27fadafc8775_ppc64le as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/kiali-rhel8@sha256:00bf086034f38940086c4f92343b5e239d590cb35b2019d71e4cdb4f0f28b61e_amd64 as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/kiali-rhel8@sha256:b4adcc404793aa643428a07885581241286ed0593ca88c2ae0593efc20a9244e_s390x as a component of OpenShift Service Mesh 2.1
  • openshift-service-mesh/kiali-rhel8@sha256:ec7762e97ecec4a90cd93393bcca856a22643c5df52e3605adb7463b27866849_ppc64le as a component of OpenShift Service Mesh 2.1

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The OpenShift Service Mesh Release Notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html

🔗 References (10)