RHSA-2022:6277MediumCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.5 security update

Published
August 31, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2022-24675 — golang: encoding/pem: fix stack overflow in Decode CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-24921 — golang: regexp: stack exhaustion via a deeply nested expression CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar CVE-2022-29526 — golang: syscall: faccessat checks wrong group CVE-2022-30629 — golang: crypto/tls: session tickets lack random ticket_age_add CVE-2022-31129 — moment: inefficient parsing algorithm resulting in DoS

🎯 Affected products37

  • OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.5-1.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-cni-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-cni-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-cni-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.5-1.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-agent-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-agent-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-agent-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-discovery-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-discovery-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-discovery-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-9.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-9.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-9.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-9.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.5-1.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debuginfo-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debuginfo-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debuginfo-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debugsource-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • +7 more not shown

✅ Remediation

The OpenShift Service Mesh Release Notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html Workaround: Sanitize the user-provided locale name before passing it to Moment.js.

🔗 References (10)