-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Low: Red Hat OpenShift Jaeger 1.17.6 container images security update
Advisory ID:       RHSA-2020:3370-01
Product:           Red Hat OpenShift Jaeger
Advisory URL:      Issue date:        2020-08-06
CVE Names:         CVE-2020-8203 CVE-2020-9283 
====================================================================
1. Summary:

An update is now available for Jaeger-1.17.

Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Jaeger is Red Hat's distribution of the Jaeger project,
tailored for installation into an on-premise OpenShift Container Platform
installation.

Security Fix(es):

* golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows
for panic (CVE-2020-9283)

* nodejs-lodash: prototype pollution in zipObjectDeep function
(CVE-2020-8203)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

jaeger-updating.html

4. Bugs fixed (https://bugzilla.redhat.com/):

1804533 - CVE-2020-9283 golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
1857412 - CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function

5. References:

https://access.redhat.com/security/cve/CVE-2020-8203
https://access.redhat.com/security/cve/CVE-2020-9283
https://access.redhat.com/security/updates/classification/#low

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXyxlitzjgjWX9erEAQg7Kg/9H+QGOZfc6UD2Oquj5cCg3cjfkDYNoMOH
FwDp8SDzCwk3kW+tjGf8NsTXoCsOMMNrvaRsK4UUujGhOHp/y8VhrvJH/ByfYrD/
2xPFiIPKwUtgII0B+UOAcUktN3dajp9zGeMTzY9ZdGWx1UvgqeGSGDsQe9BqOFCB
/OCzgnI2B7Zt/kBucWxbyoNwIJpD5pRFPD7fjtW36TRvVLYy1No5wAyb4TIOeUdO
P60kqPdsGkpnfG1GRYlGXs6mxzYNml6hZDdLs+1yrkm+l4NkJe4IAMsGjZFPU48y
RZ8QrrtIAEGVO4IqtzYFU3KRwvjxuw1tgHZwUgWK4G0TSiZFogYo2gRe9YLGtK5m
SqrG/Juh0NxZe7BgxhpiFPu6PkHpup2uro/eFxMlW5InFQHG9/VIVbXZCyjKYzpd
4kx9vBd8nq3uaAVz41ynnURor/IWVVAXyvg93olA1JLhh5pED/rT/87OQ2u6p3Ri
vvuW4w6xLtBQSfFoCzafoJu/4luJx/nADPhokcRPSRQomXSEoJnEhqxrTJySSx1p
7GvCe9d5ToT7yjHbr3jpZZoAqJCVuSzpeSDyqwCXALEEaR7YaUMiUGs3DrI/T0US
xqNNxjwD0HEJW3IZ6Tm7TZeE3nGnl9eA47f91j2ZDt0Ck9hJCCAbsqpxIgvRe3hU
OZkC5OevJdg=tbGz
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-3370:01 Low: Red Hat OpenShift Jaeger 1.17.6 container

An update is now available for Jaeger-1.17

Summary

Red Hat OpenShift Jaeger is Red Hat's distribution of the Jaeger project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic (CVE-2020-9283)
* nodejs-lodash: prototype pollution in zipObjectDeep function (CVE-2020-8203)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
jaeger-updating.html

References

https://access.redhat.com/security/cve/CVE-2020-8203 https://access.redhat.com/security/cve/CVE-2020-9283 https://access.redhat.com/security/updates/classification/#low

Package List


Severity
Advisory ID: RHSA-2020:3370-01
Product: Red Hat OpenShift Jaeger
Advisory URL: Issued Date: : 2020-08-06
CVE Names: CVE-2020-8203 CVE-2020-9283

Topic

An update is now available for Jaeger-1.17.Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1804533 - CVE-2020-9283 golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic

1857412 - CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function


Related News