First published: Thu Jun 15 2023(Updated: )
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.<br>This advisory covers the RPM packages for the release.<br>Security Fix(es):<br><li> mongo-go-driver: specific cstrings input may not be properly validated (CVE-2021-20329)</li> <li> async: Prototype Pollution in async (CVE-2021-43138)</li> <li> express: "qs" prototype poisoning causes the hang of the node process (CVE-2022-24999)</li> <li> terser: insecure use of regular expressions leads to ReDoS (CVE-2022-25858)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.