First published: Wed Feb 09 2022(Updated: )
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Origin-aggregated-logging | =3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-0552 has a medium severity rating due to the incomplete fix in the netty-codec-http package.
To fix CVE-2022-0552, ensure that the vulnerable netty-codec-http maven package is removed from your OpenShift Logging container.
CVE-2022-0552 affects the Red Hat Origin Aggregated Logging version 3.11.
The flaw in CVE-2022-0552 is due to the incomplete remediation of a previously reported issue in the netty-codec-http package.
CVE-2022-0552 may be exploitable under certain conditions due to the presence of the vulnerable version of the netty-codec-http package in the container.