RHSA-2023:4625: Important: Red Hat OpenShift Service Mesh Containers for 2.4.2 security update
Important: Red Hat OpenShift Service Mesh Containers for 2.4.2 security update
Other sources
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.Security Fix(es): envoy: OAuth2 credentials exploit with permanent validity (CVE-2023-35941) envoy: Incorrect handling of HTTP requests and responses with mixed case schemes (CVE-2023-35944) envoy: CORS filter segfault when origin header is removed (CVE-2023-35943) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4625?
The severity of RHSA-2023:4625 is high.
How can I fix the vulnerability RHSA-2023:4625?
To fix the vulnerability RHSA-2023:4625, update to Red Hat OpenShift Service Mesh Containers version 2.4.2.
Which software is affected by the vulnerability RHSA-2023:4625?
The vulnerability RHSA-2023:4625 affects Red Hat OpenShift Service Mesh, Red Hat OpenShift Service Mesh for IBM Z, and Red Hat OpenShift Service Mesh for Power.
Where can I find more information about the vulnerability RHSA-2023:4625?
You can find more information about the vulnerability RHSA-2023:4625 at the following references: [1](https://access.redhat.com/errata/RHSA-2023:4625) [2](https://bugzilla.redhat.com/show_bug.cgi?id=2217977) [3](https://bugzilla.redhat.com/show_bug.cgi?id=2217985).