RHSA-2023:3645MediumCVSS 7.8
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.2.7 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-43138 — async: Prototype Pollution in async CVE-2022-24999 — express: "qs" prototype poisoning causes the hang of the node process CVE-2022-25858 — terser: insecure use of regular expressions leads to ReDoS
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:3645
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126276
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126277
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2150323
- externalhttps://issues.redhat.com/browse/OSSM-3596
- externalhttps://issues.redhat.com/browse/OSSM-3720
- externalhttps://issues.redhat.com/browse/OSSM-3783
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3645.json