First published: Tue Jun 02 2020(Updated: )
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.<br>Security Fix(es):<br><li> nodejs-lodash: prototype pollution in defaultsDeep function leading to modifying properties (CVE-2019-10744)</li> <li> nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload (CVE-2020-7598)</li> <li> jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method (CVE-2020-11022)</li> <li> grafana: information disclosure through world-readable grafana configuration files (CVE-2020-12459)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/servicemesh-grafana | <6.2.2-36.el8 | 6.2.2-36.el8 |
redhat/servicemesh-grafana | <6.2.2-36.el8 | 6.2.2-36.el8 |
redhat/servicemesh-grafana-prometheus | <6.2.2-36.el8 | 6.2.2-36.el8 |
redhat/jaeger-v1.13.1.redhat7 | <1.el7 | 1.el7 |
redhat/kiali-v1.0.11.redhat1 | <1.el7 | 1.el7 |
redhat/jaeger-v1.13.1.redhat7 | <1.el7 | 1.el7 |
redhat/kiali-v1.0.11.redhat1 | <1.el7 | 1.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.