First published: Thu Jan 20 2022(Updated: )
Openshift Logging Bug Fix Release (5.3.3)<br>Security Fix(es):<br><li> log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)</li> <li> nodejs-ua-parser-js: ReDoS via malicious User-Agent header (CVE-2021-27292)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2022:0227 is classified as a moderate severity vulnerability.
To fix RHSA-2022:0227, update the affected software packages to the latest versions that have the security patches applied.
RHSA-2022:0227 addresses vulnerabilities CVE-2021-44832 and CVE-2021-27292.
CVE-2021-44832 is a security vulnerability that allows remote code execution via the JDBC Appender in log4j-core.
CVE-2021-27292 is a vulnerability that enables Regular Expression Denial of Service (ReDoS) via a malicious User-Agent header in nodejs-ua-parser-js.