RHSA-2022:6272MediumCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.0.11 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-31129 — moment: inefficient parsing algorithm resulting in DoS
🎯 Affected products36
- OpenShift Service Mesh 2.0
- servicemesh-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-0:2.0.11-1.el8.src as a component of OpenShift Service Mesh 2.0
- servicemesh-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-cni-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-cni-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-cni-0:2.0.11-1.el8.src as a component of OpenShift Service Mesh 2.0
- servicemesh-cni-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-istioctl-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-istioctl-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-istioctl-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-mixc-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-mixc-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-mixc-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-mixs-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-mixs-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-mixs-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-operator-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-operator-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-operator-0:2.0.11-1.el8.src as a component of OpenShift Service Mesh 2.0
- servicemesh-operator-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-agent-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-agent-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-agent-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-discovery-0:2.0.11-1.el8.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-discovery-0:2.0.11-1.el8.s390x as a component of OpenShift Service Mesh 2.0
- servicemesh-pilot-discovery-0:2.0.11-1.el8.x86_64 as a component of OpenShift Service Mesh 2.0
- servicemesh-prometheus-0:2.14.0-18.el8.1.ppc64le as a component of OpenShift Service Mesh 2.0
- servicemesh-prometheus-0:2.14.0-18.el8.1.s390x as a component of OpenShift Service Mesh 2.0
- +6 more not shown
✅ Remediation
The OpenShift Service Mesh release notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html Workaround: Sanitize the user-provided locale name before passing it to Moment.js.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2022:6272
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105075
- externalhttps://issues.redhat.com/browse/OSSM-1864
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6272.json