-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Enterprise Logging bug fix and security update (5.0.12) Advisory ID: RHSA-2022:0225-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2022:0225 Issue date: 2022-01-20 CVE Names: CVE-2021-44832 ==================================================================== 1. Summary: An update is now available for OpenShift Logging (5.0.12) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Openshift Logging Bug Fix Release (5.0.12) Security Fix(es): * log4j-core: remote code execution via JDBC Appender (CVE-2021-44832) 3. Solution: For OpenShift Container Platform 4.7 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-release-notes.html For Red Hat OpenShift Logging 5.0, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.7/logging/cluster-logging-upgrading.html 4. Bugs fixed (https://bugzilla.redhat.com/): 2035951 - CVE-2021-44832 log4j-core: remote code execution via JDBC Appender 5. JIRA issues fixed (https://issues.jboss.org/): LOG-2089 - resourceVersion is overflowing type Integer causing ES rejection [openshift-logging 5.0] 6. References: https://access.redhat.com/security/cve/CVE-2021-44832 https://access.redhat.com/security/updates/classification/#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYentwdzjgjWX9erEAQhzog//R394a37p9ejz9RI9AOvIgt57nFA4Sxd3 zNsSkz3qfHOpEXKtEJQvUashKNNxGmR5wYS6UjJIfX+cFwdC64MYjzIqppALWs3d VoWdaCc3MIY9kWwKjeSKEEGK0h2Zvu3ne+MANeJTfg5QiBuQWUx0hg6EsD9LbBCw kIiimqjJ5PEpDd7xf7SsKZ5r1lDTRG4XZfbTcyLZ6Emc2FRi0nnAfzOiUgMqml+w Gu6+M6OOli/CX8l3uIyVCkIDAaAP0YQHySbXLOEaGxvmcKw4uM6JTdXi0r6aLBPl uGToYYYUpN567db9/Vf3LmoJ1zVDVyuhgY+4nQYM7xtEP5f/5QM7oRCZo9LrlIuE k+Fh3biBtu6hJYOABRIS8O08F/acTh+w/angZXEQL5bnU3nNv9XhZ8XwtX7sD0ih BfH+70kEne/DVRlAze7edBX1aMiQJwj4NZ5rgkn+R1H7sxMfxcnbzRW+3/5ASeqX pUgMX1NwbHxxrldfAVbt+0FiLHXuC+4uZULUinhSEMA3f/2/EIRm3I/8u4kZtSKM any0U+TYwkuvxCnuKJm3OexXg39BtZmt6V9n+y5WjxoG9VyymQxuVDjV5l1htdah HwbcU+uN3aPAjHxjPuLGVx1R7mHGVhfd0qbDM8nJso6qiAX31R/ZTxXbD30yDdpe Z/Yz8ilsQmg=fr1l -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce