Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2020:3369 - Security Advisory
Issued:
2020-08-06
Updated:
2020-08-06

RHSA-2020:3369 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: Red Hat OpenShift Service Mesh security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update is now available for OpenShift Service Mesh 1.1.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.

Security Fix(es):

  • golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic (CVE-2020-9283)
  • nodejs-lodash: prototype pollution in zipObjectDeep function (CVE-2020-8203)
  • jQuery: passing HTML containing <option> elements to manipulation methods could result in untrusted code execution (CVE-2020-11023)
  • macaron: open redirect in the static handler (CVE-2020-12666)
  • golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 1.1 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh 1.1 for RHEL 7 x86_64

Fixes

  • BZ - 1804533 - CVE-2020-9283 golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic
  • BZ - 1850004 - CVE-2020-11023 jQuery: passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
  • BZ - 1850034 - CVE-2020-12666 macaron: open redirect in the static handler
  • BZ - 1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
  • BZ - 1857412 - CVE-2020-8203 nodejs-lodash: prototype pollution in zipObjectDeep function

CVEs

  • CVE-2020-8203
  • CVE-2020-9283
  • CVE-2020-11023
  • CVE-2020-12666
  • CVE-2020-14040

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat OpenShift Service Mesh 1.1 for RHEL 8

SRPM
ior-1.1.6-1.el8.src.rpm SHA-256: 1f4712459c1b642fa60e178ce431004ce9567aea22ac78556eb94e5649943a31
servicemesh-1.1.6-1.el8.src.rpm SHA-256: f21b2030c9dd0e2c2f8b50fa4b800fe0aea60f4787e8522c8b0e75971c92a093
servicemesh-cni-1.1.6-1.el8.src.rpm SHA-256: 93614609b15b295273b7e049b18255b963ade3f29f8a236d6fe1f1a729259a7f
servicemesh-grafana-6.4.3-13.el8.src.rpm SHA-256: 4fce81b8769d7bce0e1b2a7f7a1046294ea1f9729e8e6f2aa8c6712437e2e560
servicemesh-operator-1.1.6-2.el8.src.rpm SHA-256: c2c00eebc9afdd13df0e9cb9894b73a3d105df26f583800a73eab1afcfad2234
servicemesh-prometheus-2.14.0-14.el8.src.rpm SHA-256: 79e19ce2dd053dec82c2dbdadf85e43062bbdb34e1ef13b895c94a34704a8027
x86_64
ior-1.1.6-1.el8.x86_64.rpm SHA-256: d0575885b47bce4093d0088aa6145b0a4b27a7fc09cb9f9b10a5016d026a242d
servicemesh-1.1.6-1.el8.x86_64.rpm SHA-256: 6c729bdc15c0f17ee7d4cc311c5d6163df42abb6d1e5057d9a64ead7fce94089
servicemesh-citadel-1.1.6-1.el8.x86_64.rpm SHA-256: ec198c00d6034048ec6b07949bd0f74aa97e526f3d9cde6266f14b55fc909bbf
servicemesh-cni-1.1.6-1.el8.x86_64.rpm SHA-256: aeea9a057dc81eed6b636af33466b37037373c2618273070416dfbbc1bde7658
servicemesh-galley-1.1.6-1.el8.x86_64.rpm SHA-256: 32f9ec6f8aa791e5c0a303aa4d27423d6dcd789f4147d799d5cdb71797519ff6
servicemesh-grafana-6.4.3-13.el8.x86_64.rpm SHA-256: e8272a1f1317417cdc81c1cfbf46319e880b0b1a10e887d7f3a7178bb50e62c2
servicemesh-grafana-prometheus-6.4.3-13.el8.x86_64.rpm SHA-256: 5d4f5a7e5f8105315ccf8daaf358ddcfbff3ef98dffdcbc545927a921bf1f18c
servicemesh-istioctl-1.1.6-1.el8.x86_64.rpm SHA-256: aaebb42ebe2d55c1a1f8a6a8982d25967e69eeafb03619a741b78665464ab27a
servicemesh-mixc-1.1.6-1.el8.x86_64.rpm SHA-256: 240d7b6e2e87397efebc23900274e09f9713f1553d45f636998feaacec2e21ce
servicemesh-mixs-1.1.6-1.el8.x86_64.rpm SHA-256: 95909d4456b04c026f1474e49ea16dcb536e221818d81a629c53501970f12a7a
servicemesh-operator-1.1.6-2.el8.x86_64.rpm SHA-256: f553db29ab272e1f32c4c6a2ca242373671fe870cde65f2604fa6cb5d05c0f14
servicemesh-pilot-agent-1.1.6-1.el8.x86_64.rpm SHA-256: 7c5bb72f797016a9dc953872583faf09e074f10db07ddea05013cfb7f5ab0953
servicemesh-pilot-discovery-1.1.6-1.el8.x86_64.rpm SHA-256: 67af529fa42697cef2ea49887684742cac1fd89b5f8d24673401a6dc6fce5e4c
servicemesh-prometheus-2.14.0-14.el8.x86_64.rpm SHA-256: a052c8b1351463a73973e3b6b11d079c632579e41b29ddb6386302478aaaa9db
servicemesh-sidecar-injector-1.1.6-1.el8.x86_64.rpm SHA-256: 0464d8ec8f2890997f3a033492e5d88714ce2ab155f0bd1f590f351acce7dc49

Red Hat OpenShift Service Mesh 1.1 for RHEL 7

SRPM
kiali-v1.12.10.redhat2-1.el7.src.rpm SHA-256: 405412fcebeeb07f0b2005401c11f4a446028086c089bed41afb3051b8312be1
x86_64
kiali-v1.12.10.redhat2-1.el7.x86_64.rpm SHA-256: 55331845331c3b115abde7e5bda8588d33ab376972422a2c67ba19d66b981b06

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter