Important: Red Hat OpenShift distributed tracing 3.2.0 operator/operand containers update
Important: Red Hat OpenShift distributed tracing 3.2.1 operator containers security update
Important: Red Hat OpenShift distributed tracing 2.9.0 containers security update
Important: Red Hat OpenShift distributed tracing 3.0.0 operator/operand containers
Moderate: Red Hat OpenShift distributed tracing 3.1.1 operator/operand containers
Moderate: Red Hat OpenShift distributed tracing 3.3.0 operator/operand containers
Moderate: Red Hat OpenShift Distributed Tracing 2.9.0 security update
Low: Red Hat OpenShift distributed tracing 3.1.0 operator/operand containers
This release of Red Hat OpenShift distributed tracing provides these changes:Security Fix(es): nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918) eventsource: Exposure of Sensitive Information (CVE-2022-1650) moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129) follow-redirects: Exposure of Sensitive Information via Authorization Header leak (CVE-2022-0536) Moment.js: Path traversal in moment.locale (CVE-2022-24785) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
The Red Hat OpenShift Distributed Tracing 2.8 container images have been updated. CVE-2022-41717 was fixed as part of this release.<br>Users of Red Hat OpenShift Distributed Tracing 2.8 container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs, and add these enhancements.<br>Tempo Operator added as Tech Preview.<br>You can find images updated by this advisory in Red Hat Container Catalog (see<br>References).<br>Security Fix(es):<br><li> golang: net/<a href="http:" target="blank">http:</a> excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, see the CVE page(s) listed in the References section.
Release of Red Hat OpenShift distributed Tracing provides these changes:Security Fix(es): golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet (CVE-2021-29923) golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.The Red Hat OpenShift distributed tracing release notes provide information onthe features and known issues:https://docs.openshift.com/container-platform/latest/distrtracing/distributed-tracing-release-notes.html