RHSA-2022:0044: Important: Red Hat OpenShift Enterprise Logging bug fix and security update (5.3.2)
OpenShift Logging Bug Fix Release (5.3.2)Security Fix(es): rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source (CVE-2020-36327) log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern (CVE-2021-45105) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0044?
RHSA-2022:0044 addresses critical vulnerabilities including a denial of service in log4j.
How do I fix RHSA-2022:0044?
To fix RHSA-2022:0044, upgrade to the patched version of OpenShift Logging as recommended.
What vulnerabilities are addressed in RHSA-2022:0044?
RHSA-2022:0044 addresses vulnerabilities related to rubygem-bundler and log4j-core.
Is RHSA-2022:0044 applicable to all OpenShift versions?
RHSA-2022:0044 is specifically intended for OpenShift version 5.3.2 and may not apply to earlier versions.
What are the implications of ignoring RHSA-2022:0044?
Ignoring RHSA-2022:0044 could lead to exposure to denial of service attacks and potential exploitation of vulnerabilities in your logging system.