RHSA-2024:1946: Moderate: Red Hat OpenShift Service Mesh Containers for 2.5.1 security update
Moderate: Red Hat OpenShift Service Mesh Containers for 2.5.1 security update
Other sources
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.Security Fixes: follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() (CVE-2023-26159) golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786) jose-go: improper handling of highly compressed data (CVE-2024-28180) follow-redirects: Possible credential leak (CVE-2024-28849) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1946?
The severity of RHSA-2024:1946 is classified as Moderate.
How do I fix RHSA-2024:1946?
To fix RHSA-2024:1946, you should apply the latest security update for Red Hat OpenShift Service Mesh as outlined in the advisory.
What products are affected by RHSA-2024:1946?
The affected products include Red Hat OpenShift Service Mesh, Red Hat OpenShift Service Mesh for IBM Z, Red Hat OpenShift Service Mesh for Power, and Red Hat OpenShift Service Mesh for ARM 64.
What is the significance of RHSA-2024:1946?
RHSA-2024:1946 addresses security vulnerabilities within Red Hat OpenShift Service Mesh that could potentially impact your deployment.
Is there a workaround for RHSA-2024:1946 until a fix is applied?
There are no specific workarounds mentioned for RHSA-2024:1946, so applying the update is the recommended action.