-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift Service Mesh 1.1 servicemesh-proxy security update
Advisory ID:       RHSA-2020:4129-01
Product:           Red Hat OpenShift Service Mesh
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:4129
Issue date:        2020-09-30
CVE Names:         CVE-2020-25017 
====================================================================
1. Summary:

An update for servicemesh-proxy is now available for OpenShift Service Mesh
1.1.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

OpenShift Service Mesh 1.1 - x86_64

3. Description:

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio
service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.

Security Fix(es):

* envoyproxy/envoy: incorrectly handles multiple HTTP headers in requests
(CVE-2020-25017)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

The OpenShift Service Mesh release notes provide information on the
features and known issues:


5. Bugs fixed (https://bugzilla.redhat.com/):

1877613 - CVE-2020-25017 envoyproxy/envoy: incorrectly handles multiple HTTP headers in requests

6. Package List:

OpenShift Service Mesh 1.1:

Source:
servicemesh-proxy-1.1.9-1.el8.src.rpm

x86_64:
servicemesh-proxy-1.1.9-1.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-25017
https://access.redhat.com/security/updates/classification/#moderate

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBX3SE5tzjgjWX9erEAQi7OA//ayUfY2vpPfSZbgbfbLcTixXGZwXXoHZ1
TiFmcsuN9jqf6IuzHsxXnPcDg4MeYLsU0bzqn36b73rHj1NQFsXBz3OO1VUit85i
l17SZ3qoOpUxV1Yr6yDw1TCNZDs84wQCIaKEovegjBND8WNwnOV3T+Igp9zheE45
9U7D82QG+fzXJ4A0BUd1zN+wjsrzHyLbZPDrv6QBEyZyZf2/Kzlv4WJLgLDCtf5S
K/EYdzMKpOOt87tqRfs63Tfea3gYlpaa6Crw8HbI4fzFw6+xa/Isp7Wxc4gkjdoS
82fk8jgOzZ7nfHGvkwue7oTbuOSCWGqULOCXEDQN1ms4ht0V0ILHqL9yedzSaO/y
qXSQkCCCPvxlV1noMoYffwJeiVNghlHFXkx9Y8wjzGj2Dcxbb430a4rofgJ9KcmQ
SFGAwODziwIBdxaKerrLJK+b5FfBkUrJybt0uOkVp9c9hsadatQBsDoA726812Dh
R7Hw3Cw/rs2ecBaN7NDwk35d0JiLc1EXXsshb6mVjkunrHotvfl7/aFaVSJcut+a
wBHo2BW6bHa3bEqS24JwGCBkT3/9XUMlMFTwO0/qsBj9a0VtQ4taV+/rJNGhxaVV
fSCsAIxG0MemUo7O8SKFc5s9eGsL3P/ediPcT5rqpUZ+VWAfAe1SCaMlIjdu0A5f
Q8WRrEMt3vM=aPum
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-4129:01 Moderate: Red Hat OpenShift Service Mesh 1.1

An update for servicemesh-proxy is now available for OpenShift Service Mesh 1.1

Summary

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* envoyproxy/envoy: incorrectly handles multiple HTTP headers in requests (CVE-2020-25017)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

The OpenShift Service Mesh release notes provide information on the features and known issues:

References

https://access.redhat.com/security/cve/CVE-2020-25017 https://access.redhat.com/security/updates/classification/#moderate

Package List

OpenShift Service Mesh 1.1:
Source: servicemesh-proxy-1.1.9-1.el8.src.rpm
x86_64: servicemesh-proxy-1.1.9-1.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:4129-01
Product: Red Hat OpenShift Service Mesh
Advisory URL: https://access.redhat.com/errata/RHSA-2020:4129
Issued Date: : 2020-09-30
CVE Names: CVE-2020-25017

Topic

An update for servicemesh-proxy is now available for OpenShift Service Mesh1.1.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

OpenShift Service Mesh 1.1 - x86_64


Bugs Fixed

1877613 - CVE-2020-25017 envoyproxy/envoy: incorrectly handles multiple HTTP headers in requests


Related News