Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4113 - Security Advisory
Issued:
2023-07-17
Updated:
2023-07-17

RHSA-2023:4113 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Service Mesh Containers for 2.3.5 security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Service Mesh 2.3.5 Containers

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.

Security Fix(es):

  • openshift: OCP & FIPS mode (CVE-2023-3089)
  • net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x

Fixes

  • BZ - 2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
  • BZ - 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode
  • OSSM-4221 - Update 2.3 base image
  • OSSM-4290 - Release Kiali container v1.57 for OSSM 2.3

CVEs

  • CVE-2020-24736
  • CVE-2022-4304
  • CVE-2022-4450
  • CVE-2022-41723
  • CVE-2023-0215
  • CVE-2023-0361
  • CVE-2023-1667
  • CVE-2023-2283
  • CVE-2023-3089
  • CVE-2023-24329
  • CVE-2023-26604

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:14bfa79954caee54a6d23683da3614cc251b1ec4e08303e3ec4217ee322c043f
openshift-service-mesh/istio-cni-rhel8@sha256:8c14b7863467e814c833fa278d6b0be058b706b6ddd2b8bf84d6054cd354dc7a
openshift-service-mesh/istio-must-gather-rhel8@sha256:408c3da264aa721610fc9672946dbb22ce494847cec8d31b4100cf86c5b55a64
openshift-service-mesh/kiali-rhel8@sha256:424009a29b4ea3c09572d1cd89ea1a72f168db6619165f20df15702b673f0a5a
openshift-service-mesh/pilot-rhel8@sha256:fcab427703c41e5e821825e839099856aa7c4c001007d8d12e0ac8692e5644da
openshift-service-mesh/prometheus-rhel8@sha256:33abe74b18c6bea46a196143ad0b3d3885b010e3cb764b9ebcc95ee24ee61963
openshift-service-mesh/proxyv2-rhel8@sha256:300d87447c106d9762bfb3ef41adc0d419514b79eb8ee67014e9e894f2177b9a
openshift-service-mesh/ratelimit-rhel8@sha256:894c1fb3feaa27fb86ed80f648f09d6fe2ee4495977be0c776fead5b2bdee621

s390x

openshift-service-mesh/grafana-rhel8@sha256:cd047c9fcde218dd4bc7a673f7e027039e43ef67d8277517905afd25513cd51a
openshift-service-mesh/istio-cni-rhel8@sha256:afbd6f41156f3f0143b2a65972b15400d0cced3b8e19af16558b85b4c452f328
openshift-service-mesh/istio-must-gather-rhel8@sha256:a061c7046ac2b62c60e953d21e35781ac26423edc079060f98d0589b47ca681d
openshift-service-mesh/kiali-rhel8@sha256:8ef04bcf54f84e349c6f0395301d031d7c8f8a5f058103043db813ab9a06f96d
openshift-service-mesh/pilot-rhel8@sha256:a9b60e12998dbe1efa9e475f9cca96ee58436407ddc5888d83c3206d031b3c47
openshift-service-mesh/prometheus-rhel8@sha256:ffd9f7dd13481cb6f9d67d83e845bae408e112d98be15fc8553a729ee48a3dfd
openshift-service-mesh/proxyv2-rhel8@sha256:8a015e6ebe3b2cf86da429f154787ae9d92d1ef567b33ab47c6f33cb0633c4c4
openshift-service-mesh/ratelimit-rhel8@sha256:f47ff32671d8eadeedc569040b19ad04fb5e65c94523cff4625154d46839c156

x86_64

openshift-service-mesh/grafana-rhel8@sha256:1abfbe1c3898a4085fae3c76a8a6831342b74680edc711c0688d48ab86ffa5a9
openshift-service-mesh/istio-cni-rhel8@sha256:411d0566a7c16469ded33d4f8b3b893d7f0ecc1363b033f711eaddacecca33d8
openshift-service-mesh/istio-must-gather-rhel8@sha256:68362d4be19bbae7d5d31ebb1328f4910957ea8b85120ee3e43c66c053a80810
openshift-service-mesh/kiali-rhel8@sha256:7333a3c2814ce860254f19a79d0ddea884703d4152ec6bc75a2637d11ab9c8f2
openshift-service-mesh/pilot-rhel8@sha256:fd90eda22dfaa7630540794a9ba30a38e81fc78269157ca92e002e8d384f8482
openshift-service-mesh/prometheus-rhel8@sha256:6226c81f65bbd972517be75a5e58b12f0279d76913f937a29613d71db8f0a0f4
openshift-service-mesh/proxyv2-rhel8@sha256:0bd7384d18ac426b3cfc1916c86a58c492e43a82c5ae7469f5508a74b7ee0b92
openshift-service-mesh/ratelimit-rhel8@sha256:2e71b4d7783b783c2c0a292d78dff3048ecbd4c74c93a2f66c519b021a4c0b68

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility