Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10907 - Security Advisory
Issued:
2024-12-10
Updated:
2024-12-10

RHSA-2024:10907 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Low: Red Hat OpenShift Service Mesh Containers for 2.4.13

Type/Severity

Security Advisory: Low

Topic

Red Hat OpenShift Service Mesh Containers for 2.4.13

This update has a security impact of Low. A Common Vulnerability Scoring system (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.

Security Fix(es):

  • openshift-istio-kiali-rhel8-container: regular expression denial of service (CVE-2024-21538)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x
  • Red Hat OpenShift Service Mesh for ARM 64 2 aarch64

Fixes

  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service

CVEs

  • CVE-2019-12900
  • CVE-2024-10041
  • CVE-2024-10963
  • CVE-2024-21538
  • CVE-2024-50602

References

  • https://access.redhat.com/security/updates/classification/#low

aarch64

openshift-service-mesh/grafana-rhel8@sha256:7c34b4c894c44071539d83dbe3d1b6fa831747d8d6fd36049bfcaba1a41352b0
openshift-service-mesh/istio-cni-rhel8@sha256:365fb88bfa7627e7a88152f1e29e0ee8be10a0202097dded7e1d098e9860be2c
openshift-service-mesh/kiali-rhel8@sha256:7108cb02e6f49062f1171c0625adbe26fdcb0b309dc460cf11134203047cf753
openshift-service-mesh/pilot-rhel8@sha256:bd1d6ec7cab78f439e27e5f3368b1e3f74f30e194adc580368e4d4708d598d25
openshift-service-mesh/proxyv2-rhel8@sha256:3da3c161efbc4ff091ae8a32d7ce65d4ba4778d611513cb471b79b4b2a506fe0
openshift-service-mesh/ratelimit-rhel8@sha256:f794ffed7e90be35231eb9bf8bcf9c196f3ee63619e3aac03a00c1d2ed4e28e4

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:6242cee76e23f4ec6361d9ab652fff0e5e88640f535436fdf4b5213a516db091
openshift-service-mesh/istio-cni-rhel8@sha256:4eb83e92496d40e91a4ebc29afb8629b7d0ae4c2cd985759cdbdc1c4f663ec60
openshift-service-mesh/kiali-rhel8@sha256:c4b384206adece2b3b854600f11e63f345aeb0c7e5e2eb584151e600c89180ba
openshift-service-mesh/pilot-rhel8@sha256:3a43713c2849173f6cdf216d7bf370b54afda00b640d1d34096d953326bf8414
openshift-service-mesh/proxyv2-rhel8@sha256:8ab022691634e7283f9f3d8be1ae926e0435291ca2a0da963528510d402b5937
openshift-service-mesh/ratelimit-rhel8@sha256:f280141fb58347835ad79002475d6ab638e637e3e95fb45f239b611c228c6cf4

s390x

openshift-service-mesh/grafana-rhel8@sha256:0c9e77ddaba99d84f0233172e1700361be068510fcec34e8b04c6f61f668c4ad
openshift-service-mesh/istio-cni-rhel8@sha256:4e751e50e70aeed40e10f506e7cd71fd63b3a38564949948d227405f39128d4d
openshift-service-mesh/kiali-rhel8@sha256:5037323af6ba1e5ecd2d57db89167f486101c3edd6a759a29b57bdf42899cb1e
openshift-service-mesh/pilot-rhel8@sha256:cbde432fb47697e56c1756fef2605b388a426c02f078dcc354fe990aa6da09fb
openshift-service-mesh/proxyv2-rhel8@sha256:e9b70a5f51e21448578db6eaca0b6e7218550a01e0a59e63876f6b67ec467e51
openshift-service-mesh/ratelimit-rhel8@sha256:adc7753eb50bd022b2be6399eb88d2040694df8c14e60b16e2035718f7617767

x86_64

openshift-service-mesh/grafana-rhel8@sha256:038ff3272abfdae58e975df71981217356cd6f83d5545a7a3ce5c7bb59e8943e
openshift-service-mesh/istio-cni-rhel8@sha256:0d8f01448c9521e550fc07d615a13bb0cd5d52adf7580b38736a5c009add80cd
openshift-service-mesh/kiali-rhel8@sha256:c705ca948677f9f0d5540a7a920873cb98ec357ddfa479042adeedf2032b340b
openshift-service-mesh/pilot-rhel8@sha256:f30111a3dc7c5b1d327acff9d2c2052162e71654f350723e85a85e2aafa1b544
openshift-service-mesh/proxyv2-rhel8@sha256:52dbe354d1ffb466c53de1d30968f844fdcaecd9de275e706898676a451e962a
openshift-service-mesh/ratelimit-rhel8@sha256:122b49c3269dbf9f95087e60ea7c97ef574ec06c6c5ec6fd86d2a47677529f77

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility