Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Red Hat OpenShift 5.4 RHSA-2022-1461-01 Critical Denial of Service Issue

red hat
Calendar Grey April 21, 2022
Dist Redhat Esm H88
Red Hat OpenShift upgrades Logging Engine 5.4 to tackle critical vulnerabilities, boosting overall product safety.
Logging Subsystem 5.4 - Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Important

Solution

For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes

For Red Hat OpenShift Logging 5.4, see the following instructions to apply this update:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/logging/cluster-logging-upgrading

Summary

Logging Subsystem 5.4 - Red Hat OpenShift
Security Fix(es):
* kubeclient: kubeconfig parsing error can lead to MITM attacks (CVE-2022-0759)
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2022-0759 https://access.redhat.com/security/cve/CVE-2022-21698 https://access.redhat.com/security/updates/classification#important

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2022:1461-01
Product: Logging Subsystem for Red Hat OpenShift
Issue date: 2022-04-20

Topic

Logging Subsystem 5.4 - Red Hat OpenShiftRed Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter

2058404 - CVE-2022-0759 kubeclient: kubeconfig parsing error can lead to MITM attacks

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

LOG-1774 - The collector logs should be excluded in fluent.conf

LOG-1896 - CLO panic: runtime error: slice bounds out of range [:-1]

LOG-1899 - http.max_header_size set to 128kb causes communication with elasticsearch to stop working

LOG-1912 - Vector image ref breaks 5.3 build

LOG-1918 - Alert `FluentdNodeDown` always firing

LOG-1919 - Logging link is not removed when CLO is uninstalled or its instance is removed

LOG-2026 - No datapoint for CPU on openshift-logging dashboard

LOG-2052 - [vector]Infra logs aren't collected correctly

LOG-2056 - Wrong certificates used by fluentd when log forwarding to external Elasticsearch and defined structuredTypeKey

LOG-2069 - [release-5.4]Log collected dashboard displays wrong namespace

LOG-2070 - [Vector] Collector pods fail to start when a ClusterLogForwarder is created to forward logs to Kafka.

LOG-2071 - [release-5.4] The configmap grafana-dashboard-cluster-logging can not be updated

LOG-2072 - [Vector] Collector pods fail to start when a ClusterLogForwarder instance is created to forward logs to multiple log stores.

LOG-2076 - [Vector] Basic auth credentials are not added to the generated Vector config

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here