Logging Subsystem 5.6.0 - Red Hat OpenShift
- logging-view-plugin-container: loader-utils: prototype pollution in function parseQuery in parseQuery.js (CVE-2022-37601)
- logging-elasticsearch6-container: jackson-databind: denial of service via a large depth of nested objects (CVE-2020-36518)
- logging-loki-container: various flaws (CVE-2022-2879 CVE-2022-2880 CVE-2022-41715)
- logging-loki-container: golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664)
- golang: net/url: JoinPath does not strip relative path components in all circumstances (CVE-2022-32190)
- org.elasticsearch-elasticsearch: jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003)
- org.elasticsearch-elasticsearch: jackson-databind: use of deeply nested arrays (CVE-2022-42004)