-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat Kiali for OpenShift Service Mesh 2.0 security update
Advisory ID:       RHSA-2022:5913-01
Product:           Red Hat OpenShift Service Mesh
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:5913
Issue date:        2022-08-08
CVE Names:         CVE-2022-31129 
====================================================================
1. Summary:

An update for openshift-istio-kiali-rhel8-container is now available for
OpenShift Service Mesh 2.0.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat Kiali for OpenShift Service Mesh is Red Hat's distribution of the
Istio service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.

This advisory covers containers for the release.

Security Fix(es):

* moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-1826 - Rebuild Kiali Server container 1.24 to pick up base image CVE fixes

6. References:

https://access.redhat.com/security/cve/CVE-2022-31129
https://access.redhat.com/security/updates/classification/#moderate

7. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYvD8NdzjgjWX9erEAQhH/A//dkJC9hOk1DuHGoeP63G+pANu++mC9CUC
MOg7X4rAq8K70dHHRaUsQj7GNf/waAh+z2BRTump8zNBA0QV9psNQFunSbvGLT0F
ImfhaZtXvotCEB/Dv9EdnQu04MuoXNTYXYJilAr7kpzll6tu2lNh4Q/lTPo4nFvs
uI6s0sop4wWnBsrWHVKbVLCKhtrZJCsI0xd5r36nGbBx80AL3wYaDmyu4ZiLEPTX
3600Bf13cg9s1fbk+lUwVhby9WyTJi/fUSxyBlUyDxYX6LTeyPl7rgt1VH9nH9e9
JevKENtBYAyvfvpajxg3r2XeQrE+WJwEOQVMQVtSDXW01rHzC4oRNT4/7oOmcvem
vvCj9eWarYtILH/RaRBIslU/ic9xb0P+cOp+y3WQ/aebczDZXt8jOBRfk99sGdjT
HdAlHJ3LuqsZUElhrV8RDh4371IaEFk18Y4cDp1KeZH0JMTTlMUUm5hZN7jL845Z
N45BY0nt+f82WB2tm5uN8aUFw6qz9vOhWiqOR5oYwZYUrble68qUbffMKW52dKEv
KxIyyf5Xel2MDueupLpPqSKbc1Btu1/5E/h6YSxanPZjh1S2nnC6CkCau5A94Pge
RE0e+g1+NPoNW4ORzhssve+Rp517sQIx3XTinlUiQTD4NgJojb065+CIsj4aW+eN
HDishDluEdU=JCIa
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-5913:01 Moderate: Red Hat Kiali for OpenShift Service

An update for openshift-istio-kiali-rhel8-container is now available for OpenShift Service Mesh 2.0

Summary

Red Hat Kiali for OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
This advisory covers containers for the release.
Security Fix(es):
* moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-31129 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2022:5913-01
Product: Red Hat OpenShift Service Mesh
Advisory URL: https://access.redhat.com/errata/RHSA-2022:5913
Issued Date: : 2022-08-08
CVE Names: CVE-2022-31129

Topic

An update for openshift-istio-kiali-rhel8-container is now available forOpenShift Service Mesh 2.0.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-1826 - Rebuild Kiali Server container 1.24 to pick up base image CVE fixes


Related News