-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Service Mesh 2.0.11 security update Advisory ID: RHSA-2022:6272-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2022:6272 Issue date: 2022-08-31 CVE Names: CVE-2022-24785 CVE-2022-31129 ==================================================================== 1. Summary: An update is now available for Red Hat OpenShift Service Mesh 2.0.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: 2.0 - ppc64le, s390x, x86_64 3. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation. This advisory covers the RPM packages for the release. Security Fix(es): * moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) * Moment.js: Path traversal in moment.locale (CVE-2022-24785) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: The OpenShift Service Mesh release notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html 5. Bugs fixed (https://bugzilla.redhat.com/): 2072009 - CVE-2022-24785 Moment.js: Path traversal in moment.locale 2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS 6. JIRA issues fixed (https://issues.jboss.org/): OSSM-1864 - RPM Release for Maistra 2.0.11 7. Package List: 2.0: Source: servicemesh-2.0.11-1.el8.src.rpm servicemesh-cni-2.0.11-1.el8.src.rpm servicemesh-operator-2.0.11-1.el8.src.rpm servicemesh-prometheus-2.14.0-18.el8.1.src.rpm servicemesh-proxy-2.0.11-1.el8.src.rpm ppc64le: servicemesh-2.0.11-1.el8.ppc64le.rpm servicemesh-cni-2.0.11-1.el8.ppc64le.rpm servicemesh-istioctl-2.0.11-1.el8.ppc64le.rpm servicemesh-mixc-2.0.11-1.el8.ppc64le.rpm servicemesh-mixs-2.0.11-1.el8.ppc64le.rpm servicemesh-operator-2.0.11-1.el8.ppc64le.rpm servicemesh-pilot-agent-2.0.11-1.el8.ppc64le.rpm servicemesh-pilot-discovery-2.0.11-1.el8.ppc64le.rpm servicemesh-prometheus-2.14.0-18.el8.1.ppc64le.rpm servicemesh-proxy-2.0.11-1.el8.ppc64le.rpm s390x: servicemesh-2.0.11-1.el8.s390x.rpm servicemesh-cni-2.0.11-1.el8.s390x.rpm servicemesh-istioctl-2.0.11-1.el8.s390x.rpm servicemesh-mixc-2.0.11-1.el8.s390x.rpm servicemesh-mixs-2.0.11-1.el8.s390x.rpm servicemesh-operator-2.0.11-1.el8.s390x.rpm servicemesh-pilot-agent-2.0.11-1.el8.s390x.rpm servicemesh-pilot-discovery-2.0.11-1.el8.s390x.rpm servicemesh-prometheus-2.14.0-18.el8.1.s390x.rpm servicemesh-proxy-2.0.11-1.el8.s390x.rpm x86_64: servicemesh-2.0.11-1.el8.x86_64.rpm servicemesh-cni-2.0.11-1.el8.x86_64.rpm servicemesh-istioctl-2.0.11-1.el8.x86_64.rpm servicemesh-mixc-2.0.11-1.el8.x86_64.rpm servicemesh-mixs-2.0.11-1.el8.x86_64.rpm servicemesh-operator-2.0.11-1.el8.x86_64.rpm servicemesh-pilot-agent-2.0.11-1.el8.x86_64.rpm servicemesh-pilot-discovery-2.0.11-1.el8.x86_64.rpm servicemesh-prometheus-2.14.0-18.el8.1.x86_64.rpm servicemesh-proxy-2.0.11-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 8. References: https://access.redhat.com/security/cve/CVE-2022-24785 https://access.redhat.com/security/cve/CVE-2022-31129 https://access.redhat.com/security/updates/classification/#moderate 9. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYw+LudzjgjWX9erEAQimJA//YxGrkJ7ZLyJTwbhWfuH4etK/uvnFp7ZU yY+IDwtoifbVtS7LLwFuouOJ3DhAfcZfYUJjTSU7LeygrVdv9CcskDeKzMGVSp1p XejRfkWguwgOQfRibOIWusfqGfN9URb67JgRst3vBj0VpRcEVS5Oh+JPyxR2RiLQ keRIoHcJj+4YeUlu2Bq7/RuRv1AkFhzsFiY2zc4urrtWzyl6m0Uo6gVqbJ/M7f67 fAs6tSrPtqv0HGEyle+eBCDxGOjhBqU3B4LmaVn2f4Djkwnz61JSAO1VUwjTDZqj OQiqyT+SxfkKrBC9dYzxAuGDTq7Zjsz2/cZup4oOxmlc8NkqOaAr4TPQUlriuD3s HdJDdSxA43Vn7vfwkPpj9hAu5X90VJ3hw0rraSdQeR2yfiJpnJBpWzxMaugmAiEw 7Blp98XYEQ32J1ilJ3Y6OfZ6fVuKqwAYLqf7CKi6P02SkKe9XKdbPj4YRFL8sl1w SSAoj8PAJopZt9+bdII3nzRKIb3vpzuh99B03YRDQ+XNabtr+IYEBn+4W5vdIMCu wDJ51sIABOsBxq3n/m31FoCHbeV/0Dy5NXFqjw2tBrMoD6Ax+Fk2ERd8KI8X3omD UAmHxp3YfELrgzfGo7Fq5pNhFG+HIrwDzI+WlMjPTtKg9H5rIFysYpKMYnh/8h7L uq8ENVfZoz8=OMv7 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce