Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.5.1 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2023-26159 — follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28180 — jose-go: improper handling of highly compressed data CVE-2024-28849 — follow-redirects: Possible credential leak
🎯 Affected products41
- RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:0e198b83b0fe4e2e907f0ce44223807e717369fff4a3bd09fa323afbb5200d27_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:58b025688bca67cb9de2e97a34813d59c398b8c5aa06cb11cd63c79b322f07a7_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:69cbbf2406a18f9277244cc1cc38d50dc34faaebd5d6a74cc728c6a949ef2cf5_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/grafana-rhel8@sha256:ad8da9f3b2ca43d37c25e6ac37670cfaa2e98a8d6088fccadd37e836660020e2_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:234ca069ffe78398715d16191814440da39ef08311b5e3d90c33fd604ec9c07a_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:b6a0c40c39eea955482de2cec38f6e9f2fb95ec886fc406effafb5cec581280f_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:caac8c5c9753bdbd97a52295a6a836f463c21cd1bf438173575dc4db006dab55_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-cni-rhel8@sha256:d0122af40529339e7f1b2184a94c288ed3c8b731a84f7f3cc4e8ac0dcf8d8106_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:0efd74c9c1d43ef220fa808ae34139bcb73b39181afc53a556285e627dbb7d93_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:8825ebc0110560418afeb12708c4068e9d1751be5ba858db94b5ad12846b50d6_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:c3fb0c75bc4c1915e570dc6e68e6a0dd38b05157e905e3a0bbe0fb83abd2b6fd_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-must-gather-rhel8@sha256:ddf99768023aaa4f60e43a16f9d9aa44adb91d68307f020b1dfdd92a5c11fc91_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:06890ec20acad8a9911af77b0886d61a02a96f8dcc90ecc2992c96a3a5244602_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:1690eafb1f67ea903775f66cba1c9de4275a1e70f5a985940ddcb1577348045e_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:2cb94a0220ff8d69c17f2eee8db3c6f045776d63de4dc80e1a4ab31190d5c04f_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/istio-rhel8-operator@sha256:444bf4a8adc914b762758e5f4c4b06387faf288a0f75d8c8f8413919d31c855d_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:632422660922698f9662c067e4662175a0207c1a38e7ee83ac4e6186de68890b_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:91837663c930e797947ccd9ac7b9939a212dda33918d53b857c5ac48de90f175_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:bc2d5e67dcd8fcda716f7b964dbaca1eccc4f6833199b60eadbad87219fdacbd_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-ossmc-rhel8@sha256:efeed94b8d1b84224310469a6e4be5d8db055e3f8c4e06529ba20f3e7697c955_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:07d52f116218cbfaead1559ad84e63450cedbc79823e15e3e37650090dded17e_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:326b45f0d46bd99aa22404ff9634dabefb559c68271808a2607581e6c2d73f42_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:454f36d91693411ec03f6682de6f9d47acbb172919d1b97d7ecf74795a3af827_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8-operator@sha256:4919abb410f858d91bb76654aa682a18ab9b87a6c410c5c437d2678afbbf14ee_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:44e4d5dfd252a87ca2b1ee79cf74c00e8fc7f1476f6425b3766d5858a402a8b2_ppc64le as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:4b0a937e5860713fcc3489d8d3f01eafa4d100d561793ced0d61549e872ad9c7_arm64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:cc42799b6ffa1c143314397a40b77cc5b266445c597a273847e9a8bb5c686297_s390x as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/kiali-rhel8@sha256:d885ebb70409569cf8dd77fe482e7cb46d7ca8e901e54b59bce4699216dcbd94_amd64 as a component of RHOSSM 2.5 for RHEL 8
- openshift-service-mesh/pilot-rhel8@sha256:424d46b0189803fac9b7897b27fb0f0dec6f2265f6442962e4186c68c5295e04_s390x as a component of RHOSSM 2.5 for RHEL 8
- +11 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2024:1946
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://issues.redhat.com/browse/OSSM-5541
- externalhttps://issues.redhat.com/browse/OSSM-5902
- externalhttps://issues.redhat.com/browse/OSSM-5959
- externalhttps://issues.redhat.com/browse/OSSM-5960
- externalhttps://issues.redhat.com/browse/OSSM-5961
- externalhttps://issues.redhat.com/browse/OSSM-5997
- externalhttps://issues.redhat.com/browse/OSSM-6080
- externalhttps://issues.redhat.com/browse/OSSM-6099
- externalhttps://issues.redhat.com/browse/OSSM-6101
- externalhttps://issues.redhat.com/browse/OSSM-6148
- externalhttps://issues.redhat.com/browse/OSSM-6163
- externalhttps://issues.redhat.com/browse/OSSM-6177
- externalhttps://issues.redhat.com/browse/OSSM-6261
- externalhttps://issues.redhat.com/browse/OSSM-6264
- externalhttps://issues.redhat.com/browse/OSSM-6289
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1946.json