-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift Jaeger 1.17.3 container images security update
Advisory ID:       RHSA-2020:2636-01
Product:           Red Hat OpenShift Jaeger
Advisory URL:      Issue date:        2020-06-19
CVE Names:         CVE-2020-10750 
====================================================================
1. Summary:

An update for jaeger-all-in-one-rhel7-container,
jaeger-collector-rhel7-container, and jaeger-ingester-rhel7-container is
now available for Jaeger-1.17.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Jaeger is Red Hat's distribution of the Jaeger project,
tailored for installation into an on-premise OpenShift Container Platform
installation.

Security Fix(es):

* jaegertracing/jaeger: credentials leaked to container logs
(CVE-2020-10750)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

jaeger-updating.html

4. Bugs fixed (https://bugzilla.redhat.com/):

1838401 - CVE-2020-10750 jaegertracing/jaeger: credentials leaked to container logs

5. References:

https://access.redhat.com/security/cve/CVE-2020-10750
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXuzmOtzjgjWX9erEAQidWw//W+xgbnTXobGyF72N3yhNA4avS9Kown6S
q6MaAswAP2RY8bKuIvN04YYZ/s3jgz1iaoGFtsxZyuJfp8rMyuXKd5A7H6PWEPLY
Q2kn3AAUs1N421GbV+TCo0d06eLR9Ie+du0/vubNftlEkCM1zCSkM+718YUg+TYU
6XAGNbe4AqEfWWyT/qPlb1yJdIA3+dyjHVat8KFRhXpS63XA9jF50W+tW6d4l5pc
uDwMgaQ0sfkRn1Ooa7gMufxk10hQ9yrmlZ7Uzpsf2LKQlBnoqJ23w/KZnB7oxnIN
VIaGrRV2fKfcEIZZDVCfyRPCoV3US3+6WecnjWO9OSQzyzxp9ZM2x3zsu3u1J46v
EIAfpzIUzfmWBlQLowomWEKr17InYu4IdNXysMtbNU2p5jmfP70DFh49CFaF85Rt
S2u22zhtQMhWThJwpvC5KuBZTH014uEfV29mcfLARhXurI23JZ/XijB8N3DFSxDb
bFKCSMiOQ/1iaVb3hVlr1VQGkjbueyxTAil1h6Vqm6RZ+/nSqGx/TIgfFd00Obkp
RRdJthGQO/OsQPbj2lp/mrQFrKCpqFYpZbL+8IhovhWbUIx9nlANvH/Z1bqm1lLP
hniwdObIx2lrwGRi1jYbFlX6ZQIvaP0IqO6QPfOJL4nId1kHxD6Jhwyl+cxtK3ne
3rsUdqEL5ck=xrV4
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-2636:01 Moderate: Red Hat OpenShift Jaeger 1.17.3

An update for jaeger-all-in-one-rhel7-container, jaeger-collector-rhel7-container, and jaeger-ingester-rhel7-container is now available for Jaeger-1.17

Summary

Red Hat OpenShift Jaeger is Red Hat's distribution of the Jaeger project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* jaegertracing/jaeger: credentials leaked to container logs (CVE-2020-10750)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
jaeger-updating.html

References

https://access.redhat.com/security/cve/CVE-2020-10750 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2020:2636-01
Product: Red Hat OpenShift Jaeger
Advisory URL: Issued Date: : 2020-06-19
CVE Names: CVE-2020-10750

Topic

An update for jaeger-all-in-one-rhel7-container,jaeger-collector-rhel7-container, and jaeger-ingester-rhel7-container isnow available for Jaeger-1.17.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1838401 - CVE-2020-10750 jaegertracing/jaeger: credentials leaked to container logs


Related News