Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10908 - Security Advisory
Issued:
2024-12-10
Updated:
2024-12-10

RHSA-2024:10908 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Moderate: Red Hat OpenShift Service Mesh Containers for 2.5.7

Type/Severity

Security Advisory: Moderate

Topic

Red Hat OpenShift Service Mesh Containers for 2.5.7

This update has a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.

Security Fix(es):

  • kiali-ossmc-container: regular expression denial of service (CVE-2024-21538)
  • openshift-istio-kiali-rhel8-container: regular expression denial of service (CVE-2024-21538)
  • openshift-istio-kiali-rhel8-container: Improper input validation in PostCSS (CVE-2023-44270)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x
  • Red Hat OpenShift Service Mesh for ARM 64 2 aarch64

Fixes

  • BZ - 2324550 - CVE-2024-21538 cross-spawn: regular expression denial of service
  • BZ - 2326998 - CVE-2023-44270 PostCSS: Improper input validation in PostCSS

CVEs

  • CVE-2019-12900
  • CVE-2023-44270
  • CVE-2024-10041
  • CVE-2024-10963
  • CVE-2024-21538
  • CVE-2024-50602

References

  • https://access.redhat.com/security/updates/classification/#moderate

aarch64

openshift-service-mesh/grafana-rhel8@sha256:95b4c7126430eba412434b59f69ff7be7530cb29e375010246ee94dec28bffbe
openshift-service-mesh/istio-cni-rhel8@sha256:32f1666a614eb515a908017441536f88cfe62cf1bc2a873c9a56246534b27b10
openshift-service-mesh/kiali-ossmc-rhel8@sha256:1305d0cf582626872f4cbff79d4cbbfab463fd5966b362dc2ea378b904dcd26e
openshift-service-mesh/kiali-rhel8@sha256:7c7de8c9cb69adc723612d39680a9f4fd1a874cd65ff8711d179e6dbe82eba42
openshift-service-mesh/pilot-rhel8@sha256:f375c15592d67b6ea42a853ce9d9003fdc7559aa3c9383ca93c528c66db3a4fc
openshift-service-mesh/proxyv2-rhel8@sha256:9414beb2c77ddc54c49b47e9e5a5faccc59515cf8e7dd36fad5d453d6d2fa456
openshift-service-mesh/ratelimit-rhel8@sha256:77432392ca3e87d5bbe35b700df19699bf7e4bd78439829edcc437b1361c22e7

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:930c1bf27855cae0d310378a7b3c9d3d90cb387bb63fe1faa396aa849cc18871
openshift-service-mesh/istio-cni-rhel8@sha256:2970ea16ea4e83dca64c8a24cfe7fd49a68d8a90313885ef75a28df64f01a5f0
openshift-service-mesh/kiali-ossmc-rhel8@sha256:27cd1b95e89cb2bff31a7cb54a7e32775c6e380d9fc4fbc81d80610f4e864715
openshift-service-mesh/kiali-rhel8@sha256:bb6ea50838393af09b0b419186c2cecf9ed2cda9b3226d7792a4dc1e7aeff935
openshift-service-mesh/pilot-rhel8@sha256:4fec853a7d8c5c3251f46924d28f4ccdc3dd0133e58429f328692d3a3ae504a4
openshift-service-mesh/proxyv2-rhel8@sha256:e3c8efe0b0b41bf0b75e025fad0a94e1b8a937aaa391ce459d05dee811c74e4e
openshift-service-mesh/ratelimit-rhel8@sha256:c7d747212f5bf832c3506fea424750c96fed4cf3802e9ff8985cb2c7ca325486

s390x

openshift-service-mesh/grafana-rhel8@sha256:33e4fdbbf154909d18390fed53c4bcc4babf5977e193fdca05e072920ca31fe6
openshift-service-mesh/istio-cni-rhel8@sha256:06b141f66f12abd830c5a0467942976ac915fc6ab6c07be87968de36831b844d
openshift-service-mesh/kiali-ossmc-rhel8@sha256:519e79e620ed329091b262235d3cbd917dc407e8102d08a6e75d75c45f556559
openshift-service-mesh/kiali-rhel8@sha256:9dd1a11b90f887678ab7b2f10e55b33cc16a19b9ee245c02a1267c9232fb2e3f
openshift-service-mesh/pilot-rhel8@sha256:09e1ab6607a6182800880c7186660342531ab929cf948043ed4d496aa637ba28
openshift-service-mesh/proxyv2-rhel8@sha256:be179c679733d4f22c0339455053faa275c44c4f63ddcf68201d2bf9ca7fcb88
openshift-service-mesh/ratelimit-rhel8@sha256:356c8fb518784764a04e25c6aff2c1b447d7014234f8d9102a0ceb1325e96d1f

x86_64

openshift-service-mesh/grafana-rhel8@sha256:92f0492675293f748707aeeadb2a1bb61c8ba2b22cfef61219c7dbc566494ef5
openshift-service-mesh/istio-cni-rhel8@sha256:17a2e232eea8d25d6a6f5e16f0b1c62688fb5cb78ab291d228b559896f66fe07
openshift-service-mesh/kiali-ossmc-rhel8@sha256:a6155850d6616892f4dde572d473b77c33dcba9c906cafdf9c7096f19a7cf768
openshift-service-mesh/kiali-rhel8@sha256:35172a3af6954e6230749d3deceffd72265dd3b4f1c14825234048c9977f49c0
openshift-service-mesh/pilot-rhel8@sha256:a2eb4754633a9e503eb0917a9436c887d52fa6e8dce13693f7f1cc820f87089b
openshift-service-mesh/proxyv2-rhel8@sha256:df125a8adc5b35acbeb4e9525a39e853724db43361f5a2f0b278df49e7aaaf1a
openshift-service-mesh/ratelimit-rhel8@sha256:7712ffc35a618f03ea22f95f6f290c9cda68c222912d0d0d682df518f63fd5ee

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility