RHSA-2024:10908: Moderate: Red Hat OpenShift Service Mesh Containers for 2.5.7
Moderate: Red Hat OpenShift Service Mesh Containers for 2.5.7
Other sources
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.<br>Security Fix(es):<br><li> kiali-ossmc-container: regular expression denial of service (CVE-2024-21538)</li> <li> openshift-istio-kiali-rhel8-container: regular expression denial of service (CVE-2024-21538)</li> <li> openshift-istio-kiali-rhel8-container: Improper input validation in PostCSS (CVE-2023-44270)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:10908?
The severity of RHSA-2024:10908 is classified as moderate.
How do I fix RHSA-2024:10908?
To fix RHSA-2024:10908, update the affected Kiali container to the latest patched version.
Which products are affected by RHSA-2024:10908?
The affected products include Red Hat OpenShift Service Mesh and its variants for IBM Z, Power, and ARM 64.
What type of vulnerability is addressed in RHSA-2024:10908?
RHSA-2024:10908 addresses security vulnerabilities affecting the Kiali OSSMC container.
When was RHSA-2024:10908 released?
RHSA-2024:10908 was released to address security issues identified in the specified containers.