RHSA-2023:5175: Important: Red Hat OpenShift Service Mesh 2.2.10 security update
Important: Red Hat OpenShift Service Mesh 2.2.10 security update
Other sources
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.Security Fix(es): envoy: OAuth2 credentials exploit with permanent validity (CVE-2023-35941) envoy: Incorrect handling of HTTP requests and responses with mixed case schemes (CVE-2023-35944) envoy: HTTP/2 memory leak in nghttp2 codec (CVE-2023-35945) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:5175?
The severity of RHSA-2023:5175 is high.
What is the vulnerability addressed by RHSA-2023:5175?
The vulnerability addressed by RHSA-2023:5175 is not specified.
How do I fix RHSA-2023:5175?
To fix RHSA-2023:5175, apply the security update provided by Red Hat.
Where can I find more information about RHSA-2023:5175?
You can find more information about RHSA-2023:5175 in the references provided:
What are the references for RHSA-2023:5175?
The references for RHSA-2023:5175 are: 1. [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:5175) 2. [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2217977) 3. [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2217983)