Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.3.1 Containers security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-3962 — kiali: error message spoofing in kiali UI CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-39278 — Istio: Denial of service attack via a specially crafted message CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2023:0542
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132867
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2148199
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2148661
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156729
- externalhttps://issues.redhat.com/browse/OSSM-1977
- externalhttps://issues.redhat.com/browse/OSSM-2083
- externalhttps://issues.redhat.com/browse/OSSM-2147
- externalhttps://issues.redhat.com/browse/OSSM-2169
- externalhttps://issues.redhat.com/browse/OSSM-2170
- externalhttps://issues.redhat.com/browse/OSSM-2179
- externalhttps://issues.redhat.com/browse/OSSM-2184
- externalhttps://issues.redhat.com/browse/OSSM-2188
- externalhttps://issues.redhat.com/browse/OSSM-2189
- externalhttps://issues.redhat.com/browse/OSSM-2190
- externalhttps://issues.redhat.com/browse/OSSM-2232
- externalhttps://issues.redhat.com/browse/OSSM-2241
- externalhttps://issues.redhat.com/browse/OSSM-2251
- externalhttps://issues.redhat.com/browse/OSSM-2308
- externalhttps://issues.redhat.com/browse/OSSM-2315
- externalhttps://issues.redhat.com/browse/OSSM-2324
- externalhttps://issues.redhat.com/browse/OSSM-2335
- externalhttps://issues.redhat.com/browse/OSSM-2338
- externalhttps://issues.redhat.com/browse/OSSM-2344
- externalhttps://issues.redhat.com/browse/OSSM-2375
- externalhttps://issues.redhat.com/browse/OSSM-2376
- externalhttps://issues.redhat.com/browse/OSSM-535
- externalhttps://issues.redhat.com/browse/OSSM-827
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0542.json