RHSA-2022:7055MediumCVSS 9.8
Red Hat Security Advisory: RHOSDT 2.6.0 operator/operand containers Security Update
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-3918 — nodejs-json-schema: Prototype pollution vulnerability CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2022-1650 — eventsource: Exposure of Sensitive Information CVE-2022-24785 — Moment.js: Path traversal in moment.locale CVE-2022-31129 — moment: inefficient parsing algorithm resulting in DoS
🎯 Affected products7
- Red Hat OpenShift distributed tracing 2.6
- rhosdt/opentelemetry-collector-rhel8@sha256:19b497addaa9210f2b2048421a5a8ef1a8748bbb0884af10e23c59473dda544b_ppc64le as a component of Red Hat OpenShift distributed tracing 2.6
- rhosdt/opentelemetry-collector-rhel8@sha256:2089cab411ac3fc66784bacdf080ed6ff51d0a4450cc7f246915e96ed6cf8665_s390x as a component of Red Hat OpenShift distributed tracing 2.6
- rhosdt/opentelemetry-collector-rhel8@sha256:9bc1969a7862230282b9f8b902906e51cb0fdb3e3c368579a580eaccaacc7b03_amd64 as a component of Red Hat OpenShift distributed tracing 2.6
- rhosdt/opentelemetry-rhel8-operator@sha256:3ed70e814b9458affbf3ad5057a741b9f453095220c6548e2bd2960a6cdf6314_s390x as a component of Red Hat OpenShift distributed tracing 2.6
- rhosdt/opentelemetry-rhel8-operator@sha256:6c35a77e6118ba050a01e0dd5f0f6cca20211ac513cb4d92ae4058f78459610d_ppc64le as a component of Red Hat OpenShift distributed tracing 2.6
- rhosdt/opentelemetry-rhel8-operator@sha256:74d8fed59e7ed6389bfbf08bd6279b035f18fddd82056f597e6d34ccbb99c865_amd64 as a component of Red Hat OpenShift distributed tracing 2.6
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Sanitize the user-provided locale name before passing it to Moment.js.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2022:7055
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2085307
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105075
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7055.json