-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Enterprise Logging bug fix and security update (5.2.6) Advisory ID: RHSA-2022:0230-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2022:0230 Issue date: 2022-01-21 CVE Names: CVE-2021-27292 CVE-2021-44832 ==================================================================== 1. Summary: An update is now available for OpenShift Logging (5.2.6) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: OpenShift Logging Bug Fix Release (5.2.6) Security Fix(es): * nodejs-ua-parser-js: ReDoS via malicious User-Agent header (CVE-2021-27292) * log4j-core: remote code execution via JDBC Appender (CVE-2021-44832) 3. Solution: For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html For Red Hat OpenShift Logging 5.2, see the following instructions to apply this update: https://docs.openshift.com/container-platform/4.7/logging/cluster-logging-upgrading.html 4. Bugs fixed (https://bugzilla.redhat.com/): 1940613 - CVE-2021-27292 nodejs-ua-parser-js: ReDoS via malicious User-Agent header 2035951 - CVE-2021-44832 log4j-core: remote code execution via JDBC Appender 5. JIRA issues fixed (https://issues.jboss.org/): LOG-2104 - fluentd crashing after upgrade to openshift-logging 5.2.4-17 6. References: https://access.redhat.com/security/cve/CVE-2021-27292 https://access.redhat.com/security/cve/CVE-2021-44832 https://access.redhat.com/security/updates/classification/#moderate 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYetA9tzjgjWX9erEAQiVZBAApI8YxlFisRzsPzjTMzeUBL65aliPPCqt 1ET7dz4IJdgg+RfMwATZfCxPb1C2xmYw7dRts7g8yzXvMAc2vyowTs7Zio8VRZRm UJxS9YuqaSVXKIBn351TPjkrGp/k2tHfuvSRiAvoyVLHozJ39HvNq8d93JcTe2rG X5qeTQZsG73EaGnbe7A0U/VU6h1HX7bXwzLgsBDBr6TVcujJoW3QPmZsudoymFzB MqBgg57GnP95qGrJXRatMRxcqrge4ApH+rdbvHQ95PWYBQ3ye4uVNc9Wruo2Km+Q wV5qfNzG3/4C2VDGNj8o0PX54b8fXuOaOQpI/I2HeFVTBl8CyNXNNo0o+DpgDtkF zKREo2p6HNnRS12NZ8FnW4leACxQXDEoUArX8e7KUPZuFqgL9APH/xV2FlaNwm1P w+NChhGWTrGYu4Yj+qMSeYoLOT1FipM0iUGKCt2+dF1XWaHTzFUSOIxAfF9VXlsv cPlYbvKZg/YBRO9VbeQ2u2q8AZSbniD+6jY3xSM/BY6r68qqhh0Uc+Zhu3ErweGq CEkJtQUjGeVOyPLlLbZLShSyXyBKu57ehCqujnJj7c3ujwrrEHUGYo8s3a0q6cY8 Ws7YYmkkSvDSR9hcNMssiiLCahFM4SfCYCe0gmt6XdLeuVc2S7Zz8qxPnKBDLWhe Z0LfPjvL1tAëcC -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce