-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift Service Mesh Containers for 2.4.1 security update
Advisory ID:       RHSA-2023:4114-01
Product:           RHOSSM
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:4114
Issue date:        2023-07-17
CVE Names:         CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 
                   CVE-2023-0215 CVE-2023-0361 CVE-2023-1667 
                   CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 
                   CVE-2023-26604 
====================================================================
1. Summary:

Red Hat OpenShift Service Mesh 2.4.1 Containers
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio
service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.

Security Fix(es):

* openshift: OCP & FIPS mode (CVE-2023-3089)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2212085 - CVE-2023-3089 openshift: OCP & FIPS mode

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-3936 - [kiali] do not hardcode label names
OSSM-4220 - Update 2.4 base image
OSSM-4291 - Release Kiali container v1.65 for OSSM 2.4

6. References:

https://access.redhat.com/security/cve/CVE-2020-24736
https://access.redhat.com/security/cve/CVE-2022-4304
https://access.redhat.com/security/cve/CVE-2022-4450
https://access.redhat.com/security/cve/CVE-2023-0215
https://access.redhat.com/security/cve/CVE-2023-0361
https://access.redhat.com/security/cve/CVE-2023-1667
https://access.redhat.com/security/cve/CVE-2023-2283
https://access.redhat.com/security/cve/CVE-2023-3089
https://access.redhat.com/security/cve/CVE-2023-24329
https://access.redhat.com/security/cve/CVE-2023-26604
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

7. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJktcNIAAoJENzjgjWX9erEKzsP/Al1BBOrx+hly9EE+Q+kiji4
ESjWKG0ORhbu2nILzcue5+NM1LnDU0xRPdLji9lRBnlw9rqxp6qmIDbKbZfAOJky
IOFHUCQWu8xsoQJr/Bnyu1l4ngQ1adDzvUe6JYQBltDOJd9o3OgMgF5octD88ZoG
m+sIZmZpCO8bhHXM9d+/ANhNCcw07bM6jsTUmvaXLZQ1WfBFBf87C7FoMlGi4NBz
4o6TyQPGTnChN1sIvcWw0msrDhA0A5ob6CETCkfVdqhdeMlFE7+z4dJzfYATW02P
U7qEURCWMjDZZ8Kb88S6J0It4U/RLypO75YYh4AEcaCvJsCwlldzy5auN6dTelrA
ubDJdNVWyJviAMxsS668X2uscDCu74Mtxgu7HxKpK8PeOuF4uJ3EZ4VaiaZ9l8+V
DXnw3MjiWiNL/qqHKewBlWW9e2YLti2AR9j3Q/ufPecsFUIntprRf65s58qhuOfE
Qw3HsaktSDiaJ9/Jq6I31Zh54SQFnN3ve9Pb9SeWG/3h+ghD0opzxREq0J2jdvf2
VopSncrkEEfMajSdjOSvLiJtOAdw2Ngh4GRR8WFeqlCF2vdZuc+MNMgNSAtZLhO+
UG9NAPmLu/CHn3a7VwZlpqRcEU1K49azi9XhHZH08JhnByJrlFNMSb4WM9Fnr/Vk
02mHO+f8VFevKB9vrQE5
=KRaT
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-4114:01 Moderate: Red Hat OpenShift Service Mesh

Red Hat OpenShift Service Mesh 2.4.1 Containers Red Hat Product Security has rated this update as having a security impact of Moderate

Summary

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* openshift: OCP & FIPS mode (CVE-2023-3089)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

Package List


Severity
Advisory ID: RHSA-2023:4114-01
Product: RHOSSM
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4114
Issued Date: : 2023-07-17
CVE Names: CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604

Topic

Red Hat OpenShift Service Mesh 2.4.1 ContainersRed Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2212085 - CVE-2023-3089 openshift: OCP & FIPS mode

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-3936 - [kiali] do not hardcode label names

OSSM-4220 - Update 2.4 base image

OSSM-4291 - Release Kiali container v1.65 for OSSM 2.4


Related News