RHSA-2022:4985MediumCVSS 7.5
Red Hat Security Advisory: Cryostat 2.1.1: new Cryostat on RHEL 8 container images
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-25647 — com.google.code.gson-gson: Deserialization of Untrusted Data in com.google.code.gson-gson CVE-2022-28948 — golang-gopkg-yaml: crash when attempting to deserialize invalid input
🎯 Affected products6
- Cryostat 2 on RHEL 8
- cryostat-tech-preview/cryostat-operator-bundle@sha256:701458696ba8788f5c2516e7dd892b4bee992d3d9af6888aa6f4d6a203c8a8b8_amd64 as a component of Cryostat 2 on RHEL 8
- cryostat-tech-preview/cryostat-reports-rhel8@sha256:6634699c642304eccb56c23d5e69cb85c064d1bf05b42e36d35ba9e91ff87b82_amd64 as a component of Cryostat 2 on RHEL 8
- cryostat-tech-preview/cryostat-rhel8-operator@sha256:9e076c0cde640b4cd9a40039325fb103ac417579164aca3b93af2de5ee5a84e9_amd64 as a component of Cryostat 2 on RHEL 8
- cryostat-tech-preview/cryostat-rhel8@sha256:1e5dc2468c07b0ea10efa4568be3031f78c79fd3fef44dfe3f739299b2baf6e5_amd64 as a component of Cryostat 2 on RHEL 8
- cryostat-tech-preview/jfr-datasource-rhel8@sha256:dbeb06612d63011778a7a5545b74c347368515133ee557eb25ed84857469138c_amd64 as a component of Cryostat 2 on RHEL 8
✅ Remediation
The Cryostat 2 on RHEL 8 container images provided by this update can be downloaded from the Red Hat Container Registry at registry.redhat.io. Installation instructions for your platform are available at Red Hat Container Catalog (see References). Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2022:4985
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2080850
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088748
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_4985.json