-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat Kiali for OpenShift Service Mesh 2.1 security update
Advisory ID:       RHSA-2022:5914-01
Product:           Red Hat OpenShift Service Mesh
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:5914
Issue date:        2022-08-08
CVE Names:         CVE-2022-31129 
====================================================================
1. Summary:

Red Hat Kiali for OpenShift Service Mesh 2.1 Containers
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat Kiali for OpenShift Service Mesh is Red Hat's distribution of the
Istio service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.

This advisory covers containers for the release.

Security Fix(es):

* moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-1827 - Rebuild Kiali Server container 1.36 to pick up base image CVE fixes

6. References:

https://access.redhat.com/security/cve/CVE-2022-31129
https://access.redhat.com/security/updates/classification/#moderate

7. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYvD8INzjgjWX9erEAQg7+w/+Jg0cLF3SnW77Gts66ATmguidaogVcnbM
r5r/XXri4Vrkb8QsWCxA6wAeLZyPkkF+6ogoLNZMdoBS/VYAB5TH2mPCWsIm1wq5
3Dk7/65QcybalPxSKtMlqAZWVSBgEp1907wQms0xVCR5IN/idopXDGE8u32XgBit
CdFoeR4F7GggnA3Mizc5yUa1LNhw6dpEu9uReXIFfcF/V3zP8iT8ctMDWHW64TBQ
GGlzW88ZV7uF5G16xZ2Myh39GOtxthCEHx9Q1IqhloWiRwSo2bU13BGb/0HnZWlY
S4ugix3txzIaGqcDPINZ0TdbF4SCcv38NE+M1dcIhiGfh/CBFDGFE1hxybNFxn+f
GBW4oQFsFXIBA/+YHsh5vT1ft2lYLtZsgnxi0T6McLNZaSY0XPFJOQSNJ5U19NxA
9eDyVyowPrZiQYqaKG1lH6t71ywCq8qGOIk/fT2fbS+YChrYltyPAlptIOt2GcgJ
gkcTGy2FjMXRgH1xbC/NT2q+uaNH/BePGJ8V6NWx2B1j3lbCp+rEVzwl4iaqS79U
SuOhi9HIymh+WH/ZG+p0/yaiWk3yMNeJescQNShAvKpRqkMYP6u8ra99f3qlkJ0A
B6wh/HbocDdzsUQNsMsJ3JZyg5QCAJavrTNqFnXdUXgyCngXuvCl2NU51AqdtnlW
ta34NuM60UM=L7c3
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-5914:01 Moderate: Red Hat Kiali for OpenShift Service

Red Hat Kiali for OpenShift Service Mesh 2.1 Containers Red Hat Product Security has rated this update as having a security impact of Moderate

Summary

Red Hat Kiali for OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
This advisory covers containers for the release.
Security Fix(es):
* moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-31129 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2022:5914-01
Product: Red Hat OpenShift Service Mesh
Advisory URL: https://access.redhat.com/errata/RHSA-2022:5914
Issued Date: : 2022-08-08
CVE Names: CVE-2022-31129

Topic

Red Hat Kiali for OpenShift Service Mesh 2.1 ContainersRed Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2105075 - CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-1827 - Rebuild Kiali Server container 1.36 to pick up base image CVE fixes


Related News