First published: Thu Jan 20 2022(Updated: )
OpenShift Logging Bug Fix Release (5.1.7)<br>Security Fix(es):<br><li> nodejs-ua-parser-js: ReDoS via malicious User-Agent header (CVE-2021-27292)</li> <li> log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:0226 is classified as moderate.
To fix RHSA-2022:0226, update the affected packages to the latest version provided in the release.
RHSA-2022:0226 addresses vulnerabilities including ReDoS via malicious User-Agent header (CVE-2021-27292) and remote code execution via JDBC Appender (CVE-2021-44832).
RHSA-2022:0226 affects OpenShift Logging with specific vulnerabilities in nodejs-ua-parser-js and log4j-core components.
Yes, it is recommended to apply the updates promptly to mitigate the identified security risks associated with RHSA-2022:0226.