Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4114 - Security Advisory
Issued:
2023-07-17
Updated:
2023-07-17

RHSA-2023:4114 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Service Mesh Containers for 2.4.1 security update

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Service Mesh 2.4.1 Containers

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.

Security Fix(es):

  • openshift: OCP & FIPS mode (CVE-2023-3089)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x

Fixes

  • BZ - 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode
  • OSSM-3936 - [kiali] do not hardcode label names
  • OSSM-4220 - Update 2.4 base image
  • OSSM-4291 - Release Kiali container v1.65 for OSSM 2.4

CVEs

  • CVE-2020-24736
  • CVE-2022-4304
  • CVE-2022-4450
  • CVE-2023-0215
  • CVE-2023-0361
  • CVE-2023-1667
  • CVE-2023-2283
  • CVE-2023-3089
  • CVE-2023-24329
  • CVE-2023-26604

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:441adea2e1e1189e2b0de28cd075d118d86557cf0efaa6bc79dd0c6d6bba6ed2
openshift-service-mesh/istio-cni-rhel8@sha256:1ddf0a7fa8145d0e80f1943637415d2f582c0fb86b59b592cba2966e20dda215
openshift-service-mesh/istio-must-gather-rhel8@sha256:b48b877ab3066f1d16666925d47e684a912b7e2be414e9a46169bb64ef60b793
openshift-service-mesh/istio-rhel8-operator@sha256:0e68c5cf1ede361a9870ac9d3f4047e98c4c150772345abd393e756f17e2d549
openshift-service-mesh/kiali-rhel8@sha256:5f5be5d738c8f1754fd33941aa3d9f8bd9fc283ed25cb5ff185dcfefd8d809f2
openshift-service-mesh/kiali-rhel8-operator@sha256:600381b61bbcdea53092d5d122c43087e36cca9f70f1c113162a583122e2319d
openshift-service-mesh/pilot-rhel8@sha256:65914768066942514342d2a5b9abcd85612fe5380b42339f24b716d29ef16145
openshift-service-mesh/proxyv2-rhel8@sha256:c282a7e3899a14f18b0a28289fd816da2c5f5ff5e8699dceb01f7d4ce3c1ca04
openshift-service-mesh/ratelimit-rhel8@sha256:c75f062c0d4acb819858986436525d34f4ce22a138dff115cb4febabbb52a52d

s390x

openshift-service-mesh/grafana-rhel8@sha256:e127660d8c3e68e5a90ce309e62d8d5555af146d1c5d64c3287761aaa3b9b363
openshift-service-mesh/istio-cni-rhel8@sha256:36aa55671704c4ae1c76eec071bdacbc7eea55754cbed0bbcc196c7ecd024baf
openshift-service-mesh/istio-must-gather-rhel8@sha256:6aa38f7f3608ce31c8f7ebb463b0b86a5d6155bf54cdf1706fb0d6613b7534ea
openshift-service-mesh/istio-rhel8-operator@sha256:5e69c61fa9358aeaf5e5d5a198abafdcb4d584db1845cf79dac631fa81e15c9f
openshift-service-mesh/kiali-rhel8@sha256:789d14357d17fce1975a974f393315f190eda30977d43c2e7259687d7a0d812b
openshift-service-mesh/kiali-rhel8-operator@sha256:987ce64ae79bb71489bdde6eaaac71f90da20f5816b06df9cea4259262939fdd
openshift-service-mesh/pilot-rhel8@sha256:3fd50a976db0b4b1a4edc3449e4eb90c69e2e8fc2891c2a44a4e6288a24c171a
openshift-service-mesh/proxyv2-rhel8@sha256:292e19b8ce24e339ca683c32b0af3f5a064da65fe2d875b5ac589ff40a2477b2
openshift-service-mesh/ratelimit-rhel8@sha256:13537af70e4ce73dd832884f8e870601997a2f04b9bb8e4f33f6c0778dfbbea5

x86_64

openshift-service-mesh/grafana-rhel8@sha256:21d13e5cad4253c6fd3420b448fecc0f7bfce84e4920e622d6a003f31aad4b19
openshift-service-mesh/istio-cni-rhel8@sha256:033fc6a4200b9cc692bc8d37a9b07b93bdc82e69c428c4ae4efc50c4c2ad2474
openshift-service-mesh/istio-must-gather-rhel8@sha256:3e2633dc79218068e954a63d3de673d1c56b6cd343340b4b06b40218a1529329
openshift-service-mesh/istio-rhel8-operator@sha256:2be4c1ed685c5ab96d9924586b2575a1f888ed6508ad719ca13a59a911210118
openshift-service-mesh/kiali-rhel8@sha256:9e48cbb0c47fb2756d6d7ff271e6a4ca45ca775a9bafedda3d4e3f8ce1ff24db
openshift-service-mesh/kiali-rhel8-operator@sha256:8884a50fc13883569cf9eb1128d87c8594df081b9d0a0892fdfaacc6a1444dc8
openshift-service-mesh/pilot-rhel8@sha256:f9bd949bc7eacf757a7ce9ae4942ff61e8e73ad904ac63a064c5f91d3a991e90
openshift-service-mesh/proxyv2-rhel8@sha256:2b4f83a0ca1b2eb0e9360de2056fe2d03807988ea45a2e380dad60b10ce6cf14
openshift-service-mesh/ratelimit-rhel8@sha256:9e93b00c17c3894061ac428b149f3261d769420c62f65e021bd66a3aa51c331b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility