RHSA-2022:0226: Moderate: Red Hat OpenShift Enterprise Logging bug fix and security update (5.1.7)
OpenShift Logging Bug Fix Release (5.1.7)Security Fix(es): nodejs-ua-parser-js: ReDoS via malicious User-Agent header (CVE-2021-27292) log4j-core: remote code execution via JDBC Appender (CVE-2021-44832)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0226?
The severity of RHSA-2022:0226 is classified as moderate.
How do I fix RHSA-2022:0226?
To fix RHSA-2022:0226, update the affected packages to the latest version provided in the release.
What vulnerabilities are addressed in RHSA-2022:0226?
RHSA-2022:0226 addresses vulnerabilities including ReDoS via malicious User-Agent header (CVE-2021-27292) and remote code execution via JDBC Appender (CVE-2021-44832).
Which software is affected by RHSA-2022:0226?
RHSA-2022:0226 affects OpenShift Logging with specific vulnerabilities in nodejs-ua-parser-js and log4j-core components.
Is there a need for immediate action regarding RHSA-2022:0226?
Yes, it is recommended to apply the updates promptly to mitigate the identified security risks associated with RHSA-2022:0226.