Lucene search

K
redhatRedHatRHSA-2024:5094
HistoryAug 07, 2024 - 3:37 p.m.

(RHSA-2024:5094) Moderate: Red Hat OpenShift Service Mesh Containers for 2.6.0 security update

2024-08-0715:37:49
access.redhat.com
1
red hat openshift service mesh
istio service mesh
security update
quic-go
moby
golang
jose
memory exhaustion attack
cert signing bypass
incorrect handling
resource exhaustion

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

8.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High

Red Hat OpenShift Service Mesh is Red Hat’s distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.

Security Fix(es):

  • quic-go: memory exhaustion attack against QUIC’s connection ID mechanism(CVE-2024-22189)
  • moby: cert signing bypass(CVE-2018-12608)
  • golang: archive/zip: Incorrect handling of certain ZIP files(CVE-2024-24789)
  • jose: resource exhaustion(CVE-2024-28176)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

8.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

8.3

Confidence

High