RHSA-2022:2218: Moderate: Openshift Logging Security and Bug update Release (5.2.10)
Openshift Logging Bug Fix Release (5.2.10)Security Fix(es): kubeclient: kubeconfig parsing error can lead to MITM attacks (CVE-2022-0759) netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data (CVE-2021-37136) netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way (CVE-2021-37137) netty: control chars in header names may lead to HTTP request smuggling (CVE-2021-43797) prometheus/clientgolang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2022:2218?
RHSA-2022:2218 addresses vulnerabilities including a kubeconfig parsing error leading to MITM attacks (CVE-2022-0759) and a Bzip2Decoder restriction issue (CVE-2021-37136).
How do I fix the vulnerabilities associated with RHSA-2022:2218?
To fix the vulnerabilities associated with RHSA-2022:2218, you should update your OpenShift Logging to version 5.2.10 or later as recommended in the advisory.
What is the severity of RHSA-2022:2218?
The severity of RHSA-2022:2218 vulnerabilities ranges from moderate to high, particularly due to the potential for MITM attacks.
Are there specific components affected by RHSA-2022:2218?
Yes, RHSA-2022:2218 specifically affects components related to kubeclient and netty-codec within OpenShift Logging.
Is there an upgrade available for the vulnerabilities in RHSA-2022:2218?
Yes, an upgrade to OpenShift Logging version 5.2.10 is available to mitigate the vulnerabilities found in RHSA-2022:2218.