First published: Wed Jul 01 2020(Updated: )
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.<br>Security Fix(es):<br><li> kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service (CVE-2019-11253)</li> <li> openshift-service-mesh/istio-rhel8-operator: control plane can deploy gateway image to any namespace (CVE-2020-14306)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/servicemesh-operator | <1.1.4-3.el8 | 1.1.4-3.el8 |
redhat/servicemesh-operator | <1.1.4-3.el8 | 1.1.4-3.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:2795 is classified as important.
To fix RHSA-2020:2795, update to the remedied versions of servicemesh-operator, specifically 1.1.4-3.el8.
RHSA-2020:2795 addresses vulnerabilities related to YAML parsing that are susceptible to the 'Billion Laughs' attack.
The affected software package for RHSA-2020:2795 is servicemesh-operator version 1.1.4-3.el8.
As of the latest information available, there have been no known active exploits related to RHSA-2020:2795.