First published: Tue Mar 01 2022(Updated: )
OpenShift Logging bug fix and security update (5.1.9)<br>Security Fix(es):<br><li> jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception (CVE-2020-28491)</li> <li> origin-aggregated-logging/elasticsearch: Incomplete fix for netty-codec-http CVE-2021-21409 (CVE-2022-0552)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2022:0727 addresses vulnerabilities related to jackson-dataformat-cbor leading to potential OutOfMemoryError exceptions and an incomplete fix for certain logging issues in Elasticsearch.
To fix RHSA-2022:0727, you should apply the latest OpenShift Logging updates as recommended in the advisories.
The severity of RHSA-2022:0727 is classified as potentially critical due to OutOfMemoryError vulnerabilities that can affect system stability.
Yes, RHSA-2022:0727 can negatively impact system performance if the OutOfMemoryError occurs under heavy load conditions.
No, RHSA-2022:0727 specifically applies to OpenShift Logging versions that are affected by the identified vulnerabilities.