Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat OpenShift 2.2.10 RHSA-2023:5175-01 Important: Security Threats

red hat
Calendar Grey September 14, 2023
Dist Redhat Esm H88
Crucial announcement regarding Red Hat OpenShift Service Mesh 2.2.10 tackles significant vulnerabilities. Find out more.
Red Hat OpenShift Service Mesh 2.2.10 Red Hat Product Security has rated this update as having a security impact of Important

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.
Security Fix(es):
* envoy: OAuth2 credentials exploit with permanent validity (CVE-2023-35941)
* envoy: Incorrect handling of HTTP requests and responses with mixed case schemes (CVE-2023-35944)
* envoy: HTTP/2 memory leak in nghttp2 codec (CVE-2023-35945)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/cve/CVE-2023-35941 https://access.redhat.com/security/cve/CVE-2023-35944 https://access.redhat.com/security/cve/CVE-2023-35945 https://access.redhat.com/security/updates/classification#important

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2023:5175-01
Product: Red Hat OpenShift Service Mesh
Issue date: 2023-09-14

Topic

Red Hat OpenShift Service Mesh 2.2.10Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2217977 - CVE-2023-35941 envoy: OAuth2 credentials exploit with permanent validity

2217983 - CVE-2023-35945 envoy: HTTP/2 memory leak in nghttp2 codec

2217985 - CVE-2023-35944 envoy: Incorrect handling of HTTP requests and responses with mixed case schemes

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

OSSM-4799 - Kiali base-image update for OSSM 2.2.10

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here