First published: Wed Jul 01 2020(Updated: )
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.<br>Security Fix(es):<br><li> kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service (CVE-2019-11253)</li> <li> grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379)</li> <li> npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions (CVE-2019-16769)</li> <li> npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js (CVE-2020-7660)</li> <li> npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser (CVE-2020-7662)</li> <li> grafana: XSS annotation popup vulnerability (CVE-2020-12052)</li> <li> grafana: XSS via column.title or cellLinkTooltip (CVE-2020-12245)</li> <li> grafana: XSS via the OpenTSDB datasource (CVE-2020-13430)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/servicemesh-grafana | <6.4.3-11.el8 | 6.4.3-11.el8 |
redhat/servicemesh-grafana | <6.4.3-11.el8 | 6.4.3-11.el8 |
redhat/servicemesh-grafana-prometheus | <6.4.3-11.el8 | 6.4.3-11.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.