Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Red Hat OpenShift Service Mesh 2.2.10 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift Service Mesh 2.2.10 security update Advisory ID: RHSA-2023:5175-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2023:5175 Issue date: 2023-09-14 CVE Names: CVE-2016-3709 CVE-2020-24736 CVE-2023-1667 CVE-2023-2283 CVE-2023-2602 CVE-2023-2603 CVE-2023-3899 CVE-2023-26604 CVE-2023-27536 CVE-2023-28321 CVE-2023-28484 CVE-2023-29469 CVE-2023-32681 CVE-2023-34969 CVE-2023-35941 CVE-2023-35944 CVE-2023-35945 ===================================================================== 1. Summary: Red Hat OpenShift Service Mesh 2.2.10 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * envoy: OAuth2 credentials exploit with permanent validity (CVE-2023-35941) * envoy: Incorrect handling of HTTP requests and responses with mixed case schemes (CVE-2023-35944) * envoy: HTTP/2 memory leak in nghttp2 codec (CVE-2023-35945) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer tothe CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2217977 - CVE-2023-35941 envoy: OAuth2 credentials exploit with permanent validity 2217983 - CVE-2023-35945 envoy: HTTP/2 memory leak in nghttp2 codec 2217985 - CVE-2023-35944 envoy: Incorrect handling of HTTP requests and responses with mixed case schemes 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OSSM-4799 - Kiali base-image update for OSSM 2.2.10 6. References: https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/cve/CVE-2023-35941 https://access.redhat.com/security/cve/CVE-2023-35944 https://access.redhat.com/security/cve/CVE-2023-35945 https://access.redhat.com/security/updates/classification#important 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlA3q2AAoJENzjgjWX9erEdf0P/3QfCq+SJQ9z3HnMKY/9rgTo c2cyIMdt0PZYwcd7jAdJ1Cad0g3Oevh8bDEYhmrvtV8nitGiryhJavjA+BDFP5NF rSqRH9j2Tsp6OYvPCgHAM31A7FAQWSSBmaoCaad47qsmRGM2pyOoppxTJe7Nck2/ MU/m3eSRjHxeoZiEVsdc6O6KYiTbHuPlhoCRUzTC5DnNDPwEDMMt0XGPAeBhe75q x4rFe0CkOpNyGhrGlpioUedajBluU0LpiqDOKoGU5ZkRlg7x2+2D5q9R7M2qaDUM 1PuQ/EJZewzk9BINio1YDU7xZIJ9CzKDS0NhqxZ/8scenGpVLrX4CVC3FAM4SzfY tSkYn27WgwvyuTeioth8MdbMS4GOuUl4ebstlzVeD6zeqqvzSinA6tPz2LbAuyru 8rBad7xQPVuazWSBXzzlnbguM1t19vcinvAzU9SQtKvCwnQa4CYCzIO6KKaaG/Y7 f6s2pfMfyQlgTMLGE96xABUMK4G06IhlY78hcYCg+gmmU5q4JrLOCIV2IG7a/qZ0 52Mv3hHE0Orzn46bLjL0RLdGxyW8r+XpXHfyO3IoEATuygR1vxFpvCZHfPatbUwq mWEOLRiCxq1RmXfjzPJlkNl/NCqNFwrGwZm0YrhPXSl1Ib9vo98wkqP2Eo2NuM2F cSSMp7PgsLR/wqjocz1A =SNT2 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh Containers for 2.4.3 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Service Mesh Containers for 2.4.3 security update Advisory ID: RHSA-2023:5174-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2023:5174 Issue date: 2023-09-14 CVE Names: CVE-2016-3709 CVE-2023-2602 CVE-2023-2603 CVE-2023-2828 CVE-2023-3899 CVE-2023-27536 CVE-2023-28321 CVE-2023-28484 CVE-2023-29469 CVE-2023-32681 CVE-2023-34969 CVE-2023-35942 ===================================================================== 1. Summary: Red Hat OpenShift Service Mesh Containers for 2.4.3 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is the Red Hat distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. This advisory covers container images for the release. Security Fix(es): * envoy: gRPC access log crash caused by the listener draining (CVE-2023-35942) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system havebeen applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2217978 - CVE-2023-35942 envoy: gRPC access log crash caused by the listener draining 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OSSM-1182 - Deliver ARM images for OSSM Operator for Developer Preview OSSM-3508 - Ensure Cluster Ingress Operator can create cluster-wide SMCP OSSM-3979 - Implement envoyExtAuthzGrpc extension provider OSSM-4247 - Service details of ServiceEntry fails OSSM-4461 - Add FIPS annotation setting to kiali operator metadata OSSM-4491 - Add missing configuration options to meshConfig.extensionProviders.envoyExtAuthzHttp OSSM-4559 - Panic in conversion of extensionProviders.envoyExtAuthzHttp OSSM-4627 - Add option to disable the GatewayClass controller OSSM-4705 - Removing subset in config - Fails to save 6. References: https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/cve/CVE-2023-35942 https://access.redhat.com/security/updates/classification#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlA3quAAoJENzjgjWX9erEOOwQAJh30YjH0YDaZEftcPJRqVbJ IADT5p6J5WzGXJWullXoDcenfW1HXdV5mHlQdfGcWq33miW3vROfugDLWj841Nsd VOwQYypoNEOVLeAvnNX64oVOM/A8HOfDN4UmdLEhvF4GXdpjMI+ac93KX8EJ+IRN WCNflP75ZVneBZB7yfFnbxRHzkqH/HQNHDC687t0EC0q2h3R5vxPBuLEhCQSZzKw BgcmuT1thD3f5laYNue+axLby/+MGuW5/pEY8S0JEiZnGxisT6Ey4cSPodZ5zrSK nnCc9oVXc8flc3yCk0icd/KT7O4dlnzALyX43F4z5sNeiAJbJLdlVnMX+9tk5dG9 InLOrfgBGhzD40xVMEKSWLglRIcccUDCJKVFDXX85pf0/oonNq7I/kxsq6aMdxG+ VT5TvFPWmbEDBP+6uckcDro3rvXHbo4qDTems97mkUlBAhpKpIXsxKmGC8fnRViG +LExxiP7d9bAzxZ3CJ4e1xb4b1lA5MPjf4WJFPVnb9He8cbcJWaemt6DjN/5iCXa PX5NtAQDicBXX0A0I0mIL8HhqQY/jXpVj1XeW5gD3IBpQ7jT76LDEidk+CFRl3Q1 86lKuSfGYyczK+J2hR69KMfusaEy6DHBmp08ksUFY3Uw47WG+2WEOC/1jullIf0W j0Uaqj6CDOV+pu2LYVOe =EENm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh 2.3.6 Containers Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift Service Mesh Containers for 2.3.6 security update Advisory ID: RHSA-2023:4624-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2023:4624 Issue date: 2023-08-11 CVE Names: CVE-2023-2828 CVE-2023-35941 CVE-2023-35942 CVE-2023-35943 CVE-2023-35944 CVE-2023-35945 ===================================================================== 1. Summary: Red Hat OpenShift Service Mesh 2.3.6 Containers Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. Security Fix(es): * envoy: OAuth2 credentials exploit with permanent validity (CVE-2023-35941) * envoy: Incorrect handling of HTTP requests and responses with mixed case schemes (CVE-2023-35944) * envoy: HTTP/2 memory leak in nghttp2 codec (CVE-2023-35945) * envoy: gRPC access log crash caused by the listener draining (CVE-2023-35942) * envoy: CORS filter segfault when origin header is removed (CVE-2023-35943) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in theReferences section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2217977 - CVE-2023-35941 envoy: OAuth2 credentials exploit with permanent validity 2217978 - CVE-2023-35942 envoy: gRPC access log crash caused by the listener draining 2217983 - CVE-2023-35945 envoy: HTTP/2 memory leak in nghttp2 codec 2217985 - CVE-2023-35944 envoy: Incorrect handling of HTTP requests and responses with mixed case schemes 2217987 - CVE-2023-35943 envoy: CORS filter segfault when origin header is removed 5. References: https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-35941 https://access.redhat.com/security/cve/CVE-2023-35942 https://access.redhat.com/security/cve/CVE-2023-35943 https://access.redhat.com/security/cve/CVE-2023-35944 https://access.redhat.com/security/cve/CVE-2023-35945 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk1pfYAAoJENzjgjWX9erE200P/2Y3yaoe64sMk4EThWMQnyDf IeHQt7welubO7E6MbIF+8yclV1ckQUFL5ajX8IWtqrTvvnZjYNXmRxSubbPgrBNa MUQiyLvj6UXIsMqxaJN9n6rtz1ItbiBNK/AH6ITdN4TAHYG+fzTI58PapJ9g8urX 8Pd00dx953Jj2gU5toyw6VTR/fJp3ZCgbQxmI78FSnsN77i2/q6WOkJ0TRLcGe+z GJw62bxyNKGA1I72NoZqyt/SmIqIhfXP+ofaA4kgWP8XI4/pjL2SDvNsVC0wMNZx zQO1cZvYBDo//oZ3NBtR5YpFNZSxpDvv6eiuGOP3LNsTaXot5nAZLSkpzyCFCY9v xccDTjVSYysz/aGqa6vTjCd264P4JVMewI/rfDPfaqV3PcCrtm64YCedNTBEwXMx uMbdbW02xiX9sRa7Ln38FjvDMCfdOAHaoNOmbOnfS4erQuWF9cJxYXMGPBIk+PY4 XtxrOPONWbyFPCTspH2D+ISaibu+rK363ZacEXgZ5JOCo5H38y4BINTUPoC2cxF3 ezwQgKMLPHeCOKBlesQnoPz/EeOL0d3eeNzQvvCAnUk2GCBqazfbxOrjFlqdp9zK ugK8VgJcAFiEDeLrhYpSK88BgScJSE/p5cCKdJy3BSHugnVSRD9iKyccuowC3vcT ZlAhHXpt+D9ytCT8F+R4 =ZtLZ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh 2.3.5 Containers Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Service Mesh Containers for 2.3.5 security update Advisory ID: RHSA-2023:4113-01 Product: RHOSSM Advisory URL: https://access.redhat.com/errata/RHSA-2023:4113 Issue date: 2023-07-17 CVE Names: CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 CVE-2022-41723 CVE-2023-0215 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604 ==================================================================== 1. Summary: Red Hat OpenShift Service Mesh 2.3.5 Containers Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OSSM-4221 - Update 2.3 base image OSSM-4290 - Release Kiali container v1.57 for OSSM 2.3 6. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJktcNyAAoJENzjgjWX9erE4WUQAIQZTfB2us4/d8G99Djt6BBR oXyVuskzchRvcFr6JE0NCd3uH9B17UEyqb4XsOHeZVkC9h+zZqqPwdPzXXJFUsXn Z9cnDZniMTAS5p2ZeZ15ElXfpeojtOOFTcgCMJcYxX/YJW2R4Wk80b30IOSZnv5i t7lG6reF7RGhNr+yzm44f4PhZa6USMI5HwMXz+WEkFj6MA2I5QDVSk1WEA3ru2Gd 4y7+9XKLRsn2M0ZwrRDivQgcyIO/2DH5tD1kROkGuzje2YCsH3Ui88KB3Qe+loLp V4aNSJ2RuiPNnKPxa/NEIF1LgM7fUkk47fimaVHv0F0tbDyFDv6G9bOzsFFBnmEb wXrEXvdt5BkOoIR6TTJt109VBn0Jsjhi59m8aBEuNm4HyICUz3ReS7JQNGpuxUij xwsGqv3Wusdp12b3W8AMJIAWh8YIrEqyZ2g9NXWID8d3baRl5897OlDSoV9Y5HkE cIumyTP0cpYbepA2ijIXZGn4EBWoDNclRxmnIHfpxZJ0dXER6Jk2ChIZp+0VZp6n AqTOgTq2BPXDdb3XeQpFi1+dj1HW5AnRfDyLczdoR40YtEx4lg3Wt6mvAbiTnPvJ goVbNvhRiSv+jUMWU4CH6q54Zj7ECpADNWSJ0aHxmVkAuxLq9XS83kxIXN8XhCur 2axvNkoYyccHnR17q8rR =KGY6 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh 2.2.8 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Service Mesh 2.2.8 security update Advisory ID: RHSA-2023:4112-01 Product: RHOSSM Advisory URL: https://access.redhat.com/errata/RHSA-2023:4112 Issue date: 2023-07-17 CVE Names: CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 CVE-2022-41723 CVE-2023-0215 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604 ==================================================================== 1. Summary: Red Hat OpenShift Service Mesh 2.2.8 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed(https://bugzilla.redhat.com/): 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OSSM-4197 - [maistra-2.2] CNI installer fails if /etc/cni/multus/net.d/ doesn't exist OSSM-4222 - Update 2.2 base image OSSM-4289 - Release Kiali container v1.48 for OSSM 2.2 6. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIbBAEBCAAGBQJktcNNAAoJENzjgjWX9erE9L8P9icMA6CCbFgzAOKmlnmVRK1R 2en1CBkJC60HesUCQMQpoG0muJy4FQU1u1YH9t8/fikffOrEy/00NdvM1Ivia0qM 6JTnBrkf0sF+80f4/dWSByHNgYb0+hO1r+a3uVyWddkfCht745YCBAUcrIMV07FU UNsgwdZ2cxPU81Jyuv4Sj2i4rAzj5zC4OiS1pFEuPeWR7WMlDltGzgiMff7rxMux 1qVAeFP7Fl8vjeRTaaBkadoEPMwSSv9GvM/KO2U53kNeTBWehoN52TVL4qpBdOqH ikhocMXqGHXUn8sP9HP03kKoaUoxzxRbP8kddOBXk66ov7Tfb41xA7RK5RR7oR/3 11J1JThQY+3AXMKxOU6uNZub1sB55LUH6WUGkIkhZQ/NNmmrLaoYfWAwyZwrUROE pjHLoNQkKKD52IQb33PgOms0/ZsfdjDfGrQDoMJ/1jc8h/wMep7Zq419FG12qDI9 aYzV9BsiYnQ5lWn8CXE7lGZucONUmqaBkpRxUr7KPiHJTpUDrzCpqgCZQPDiTU1z E3R17Gzf1cOLMnyWaMRmOf1qkv4WuG9X6gJTw7PdkUrHZNsP4nnZkLLvCg8zF0Vf 4/r3r+N9VfoQ6R6iOuFBxYwfV+Df6/6suxoj3BmK8VhkbT0/K+VERxv/0kIb0q7O SNI7souDkchQl4RP17A=CxKZ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh 2.4.1 Containers Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Service Mesh Containers for 2.4.1 security update Advisory ID: RHSA-2023:4114-01 Product: RHOSSM Advisory URL: https://access.redhat.com/errata/RHSA-2023:4114 Issue date: 2023-07-17 CVE Names: CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 CVE-2023-0215 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604 ==================================================================== 1. Summary: Red Hat OpenShift Service Mesh 2.4.1 Containers Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 5. JIRAissues fixed (https://redhat.atlassian.net/jira/projects): OSSM-3936 - [kiali] do not hardcode label names OSSM-4220 - Update 2.4 base image OSSM-4291 - Release Kiali container v1.65 for OSSM 2.4 6. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJktcNIAAoJENzjgjWX9erEKzsP/Al1BBOrx+hly9EE+Q+kiji4 ESjWKG0ORhbu2nILzcue5+NM1LnDU0xRPdLji9lRBnlw9rqxp6qmIDbKbZfAOJky IOFHUCQWu8xsoQJr/Bnyu1l4ngQ1adDzvUe6JYQBltDOJd9o3OgMgF5octD88ZoG m+sIZmZpCO8bhHXM9d+/ANhNCcw07bM6jsTUmvaXLZQ1WfBFBf87C7FoMlGi4NBz 4o6TyQPGTnChN1sIvcWw0msrDhA0A5ob6CETCkfVdqhdeMlFE7+z4dJzfYATW02P U7qEURCWMjDZZ8Kb88S6J0It4U/RLypO75YYh4AEcaCvJsCwlldzy5auN6dTelrA ubDJdNVWyJviAMxsS668X2uscDCu74Mtxgu7HxKpK8PeOuF4uJ3EZ4VaiaZ9l8+V DXnw3MjiWiNL/qqHKewBlWW9e2YLti2AR9j3Q/ufPecsFUIntprRf65s58qhuOfE Qw3HsaktSDiaJ9/Jq6I31Zh54SQFnN3ve9Pb9SeWG/3h+ghD0opzxREq0J2jdvf2 VopSncrkEEfMajSdjOSvLiJtOAdw2Ngh4GRR8WFeqlCF2vdZuc+MNMgNSAtZLhO+ UG9NAPmLu/CHn3a7VwZlpqRcEU1K49azi9XhHZH08JhnByJrlFNMSb4WM9Fnr/Vk 02mHO+f8VFevKB9vrQE5 =KRaT -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh Containers for 2.4.0 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift Service Mesh Containers for 2.4.0 Advisory ID: RHSA-2023:3644-01 Product: RHOSSM Advisory URL: https://access.redhat.com/errata/RHSA-2023:3644 Issue date: 2023-06-15 CVE Names: CVE-2021-4235 CVE-2022-1705 CVE-2022-2795 CVE-2022-2879 CVE-2022-2880 CVE-2022-2995 CVE-2022-3162 CVE-2022-3172 CVE-2022-3204 CVE-2022-3259 CVE-2022-3466 CVE-2022-27664 CVE-2022-30631 CVE-2022-32148 CVE-2022-32189 CVE-2022-32190 CVE-2022-36227 CVE-2022-39229 CVE-2022-41715 CVE-2023-24540 CVE-2023-27535 ==================================================================== 1. Summary: Red Hat OpenShift Service Mesh Containers for 2.4.0 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is the Red Hat distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. This advisory covers container images for the release. Security Fix(es): * golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section. 3. Solution: For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2196027 - CVE-2023-24540 golang: html/template: improper handling of JavaScript whitespace 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OSSM-1094 - Htpasswd secret created in control plane namespace is using SHA1 OSSM-1667 - Remove deprecated cipher suites OSSM-2128 - Exclude some accessible namespaces in Kiali CR with some labelSelector OSSM-2215 - istio-cni-node never updates kubeconfig causing error adding container to network \"v2-0-istio-cni\": Unauthorized OSSM-2221 - Gateway injection does not work in control plane namespace OSSM-2254 - Fix and deprecate IOR OSSM-2274 - If two SMCPs exist in a namespace and you delete one, all child resources are deleted OSSM-2325 - Disable prometheus in the minimal example CR OSSM-2339 - Deprecated istio-operator API call in CNV OSSM-2420 - Pod locality controller fails to update pod OSSM-2436 - istio-operator reports as ready before it really is OSSM-3246 - Promote ClusterWide to GA OSSM-3288 - Implement prometheus extension provider OSSM-3291 - Implement envoyExtAuthzHttp extension provider OSSM-331 - Service Mesh IPv6 Single Stack Support OSSM-3419 - Align OSSM 2.4 with latest upstream Istio 1.16.5 release OSSM-3747 - Duplicate env vars in egress gateway deployment OSSM-3784 - Bad ownerReference in k8s Gateway Deployment & Service OSSM-3802 - GA discoverySelectors (move out of techPreview.meshConfig) OSSM-3803 - Move extensionProviders to SMCP.spec.meshConfig.extensionProvidersOSSM-3870 - OSSM must-gather improvements OSSM-3873 - [KIALI] Kiali ingress.host accepted in the SMCP but is not configured properly in Kiali CR OSSM-3934 - Prometheus and grafana not reachable from kiali OSSM-3986 - Kiali does not display all the data when SMCP is deployed with Cluster Wide mode OSSM-4037 - kiali operator base image bump OSSM-4069 - Kiali route is missing with 2.2Control Plane in 2.4 Operator on OpenShift 4.13 OSSM-566 - Supported integration with OpenShift Monitoring and BYO Prometheus OSSM-568 - Integration with (external) cert-manager 6. References: https://access.redhat.com/security/cve/CVE-2021-4235 https://access.redhat.com/security/cve/CVE-2022-1705 https://access.redhat.com/security/cve/CVE-2022-2795 https://access.redhat.com/security/cve/CVE-2022-2879 https://access.redhat.com/security/cve/CVE-2022-2880 https://access.redhat.com/security/cve/CVE-2022-2995 https://access.redhat.com/security/cve/CVE-2022-3162 https://access.redhat.com/security/cve/CVE-2022-3172 https://access.redhat.com/security/cve/CVE-2022-3204 https://access.redhat.com/security/cve/CVE-2022-3259 https://access.redhat.com/security/cve/CVE-2022-3466 https://access.redhat.com/security/cve/CVE-2022-27664 https://access.redhat.com/security/cve/CVE-2022-30631 https://access.redhat.com/security/cve/CVE-2022-32148 https://access.redhat.com/security/cve/CVE-2022-32189 https://access.redhat.com/security/cve/CVE-2022-32190 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2022-39229 https://access.redhat.com/security/cve/CVE-2022-41715 https://access.redhat.com/security/cve/CVE-2023-24540 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification#important 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZIuxO9zjgjWX9erEAQhxLg//cqi5JYtCAvOoMpkcoFT/rTGhn2s7EmPX gCNYy/Gv1EESdc4WLJs/96vXWpnRF1XA1Z+Jrn6Ojd1OcRVikWjpXtzM+2cKNoCA HZMvyxRe4R0QlcBb17XZYDN0plU+H24UGDMHengwY45K5ZRWfw7/vb3Gna3VwUgk QALQk0WLqiJUSDy0CAaFwZNKUZKZmKCmQudm8dbECA+pCKTYS22bfbuE4o2jtcTA PmFZ5sDIKTuWuzHtxT5Urbx+g6rgijP3xP1JqZXzuI9ExH7eeS7e1Sk8rH2MOXH2 E9VDmAsi2p7ffdaLRILHYPdLtt88wiE0kLjBof7i7OMBSoX70l3UEwvy9g96udbl a/GsvnKkrpEnxXyPxUm4HQQ5xHPEaFIZlAwGSwnZ7CPS0wkWu3vN513ccMF+wsgx BokeK739WjxblJRsf/fTujflEMmOzIzsM6N3yDY51hs2lAl1NFZSCjFUTwjuoNNK 7CgMoWkbCDRc0tGWvu82gJfZPnlw7lRPHYAVSNkMAPQsODTyk8FEoY9Sj8UtnI5C qKwo7TdYjTwrivRCoQJJcNZJxW6RY2NSZNev3WviJuM+tssXXkOCJaD6Eguy6UhO PElcfkRdRJW5HevW+u56ngGfBUb091Zyes7bN8E0AwFBI1CBvjzWgEFTM1i2Ce/+ A6ybAfZVB68=0l+j -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Red Hat OpenShift Service Mesh 2.2.7 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Service Mesh 2.2.7 security update Advisory ID: RHSA-2023:3645-01 Product: RHOSSM Advisory URL: https://access.redhat.com/errata/RHSA-2023:3645 Issue date: 2023-06-15 CVE Names: CVE-2021-20329 CVE-2021-43138 CVE-2022-2880 CVE-2022-4304 CVE-2022-4450 CVE-2022-24999 CVE-2022-25858 CVE-2022-27664 CVE-2022-36227 CVE-2022-39229 CVE-2022-41715 CVE-2023-0215 CVE-2023-0286 CVE-2023-0361 CVE-2023-27535 ==================================================================== 1. Summary: Red Hat OpenShift Service Mesh 2.2.7 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. This advisory covers the RPM packages for the release. Security Fix(es): * mongo-go-driver: specific cstrings input may not be properly validated (CVE-2021-20329) * async: Prototype Pollution in async (CVE-2021-43138) * express: "qs" prototype poisoning causes the hang of the node process (CVE-2022-24999) * terser: insecure use of regular expressions leads to ReDoS (CVE-2022-25858) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 1971033 - CVE-2021-20329 mongo-go-driver: specific cstrings input may not be properly validated 2126276 - CVE-2021-43138 async: Prototype Pollution in async 2126277 - CVE-2022-25858 terser: insecure use of regular expressions leads to ReDoS 2150323 - CVE-2022-24999 express: "qs" prototype poisoning causes the hang of the node process 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OSSM-3596 - Port istio-cni fix for RHEL9 to maistra-2.2 OSSM-3720 - Port egress-gateway wrong network gateway endpoints fix in maistra-2.2 OSSM-3783 - operator can deadlock when istiod deployment fails [maistra-2.2] 6. References: https://access.redhat.com/security/cve/CVE-2021-20329 https://access.redhat.com/security/cve/CVE-2021-43138 https://access.redhat.com/security/cve/CVE-2022-2880 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-24999 https://access.redhat.com/security/cve/CVE-2022-25858 https://access.redhat.com/security/cve/CVE-2022-27664 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2022-39229 https://access.redhat.com/security/cve/CVE-2022-41715 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZIuxJdzjgjWX9erEAQglEg/6A7Ceu4fLKvXl+RRcBZs1TAFYReXxYOcd KGEDPmEuS2YCS3pn4CN/CqPYcgp1YmtTrpUZxmzKoAZjInJ3kc4zG7XGim3eLBiC LUWMl7DUM9voriHCmrktjr3sMfryng7FL5i9NT8Sh0YxyeJ0DEr/3Pziyae5JezY BC1uColX7LtZUa0dLgP3Tl7lW/tEn2TwOUldmLAJwjzvECzsCelLT57DOUbeibV0 TrmGs6ZOhUDNzbLHRZuvtLXIJlL0LquR/B/KzOT7ZuawEAxMmh70t2AdS3mD4YXq GxG9b4mfq7zIYa6nvUnTcaKxM/gE0TE0Vrrk9FdUfXcpyQfZnVakLf3i5ll0XmqA 7YSSdBJIj8kccbz7DV9siJVyCMmlN/7KB0QYont4MiIvY4/ovS9pytDtuJ2xvOZ4 pTe6tF2i8S+XvI5D173I7+QoN8fUGiP3gdArRKFu7GlFXZfrgq4Yfl4wQR26tbpE CCrT1ct9Bj1IdvFSOexBzaNArh60Vpi0uUYfYg2smVPJslCNhKY9c1D0T/pLZL3b mO5ytnq/zaNPFSYS4LpuBn9qX1TXJmlNQlpm/Pnzs//YVaZbxXwvzzGC4vVr7F+r +VVlfI43X4bLKseuxToheH9UrMIJRW+aE6bFHE1ss22m9y5n/kHRK8oDb5FRur3b LOOJa1Oil6M=4VhL -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.