RHSA-2022:6272: Moderate: Red Hat OpenShift Service Mesh 2.0.11 security update
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.<br>This advisory covers the RPM packages for the release.<br>Security Fix(es):<br><li> moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)</li> <li> Moment.js: Path traversal in moment.locale (CVE-2022-24785)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6272?
The severity of RHSA-2022:6272 is considered important.
How do I fix RHSA-2022:6272?
To fix RHSA-2022:6272, update the relevant RPM packages to the specified versions as listed in the advisory.
Which packages are affected by RHSA-2022:6272?
RHSA-2022:6272 affects multiple packages including servicemesh, servicemesh-cni, and servicemesh-operator among others.
What version should I upgrade to for RHSA-2022:6272?
You should upgrade to version 2.0.11-1.el8 or 2.14.0-18.el8.1 depending on the specific package affected.
Is RHSA-2022:6272 specific to certain architectures?
Yes, RHSA-2022:6272 impacts multiple architectures including x86_64 and ppc64le.