RHSA-2023:0542HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.3.1 Containers security update

Published
January 30, 2023
Last Modified
June 21, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-3962 — kiali: error message spoofing in kiali UI CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-39278 — Istio: Denial of service attack via a specially crafted message CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps

🔗 References (34)