Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:9629 - Security Advisory
Issued:
2024-11-14
Updated:
2024-11-14

RHSA-2024:9629 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Service Mesh Containers for 2.5.6

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh Containers for 2.5.6

This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.

Security Fix(es):

  • kiali-ossmc-container: nesting-based mutation XSS vulnerability (CVE-2024-47875) (OSSM-8247)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x
  • Red Hat OpenShift Service Mesh for ARM 64 2 aarch64

Fixes

  • BZ - 2318052 - CVE-2024-47875 dompurify: nesting-based mutation XSS vulnerability

CVEs

  • CVE-2019-12900
  • CVE-2024-3596
  • CVE-2024-4032
  • CVE-2024-5535
  • CVE-2024-6232
  • CVE-2024-6923
  • CVE-2024-9355
  • CVE-2024-45490
  • CVE-2024-45491
  • CVE-2024-45492
  • CVE-2024-47875

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-service-mesh/grafana-rhel8@sha256:20c5729df345672654e0451e0cbcfbe863805fb5bb28b18cfaf3535c58e30089
openshift-service-mesh/istio-cni-rhel8@sha256:5b10adf74b4e38e9e7768d0e4178b6069e287a514118d2c01a547a82bf63bfc0
openshift-service-mesh/istio-must-gather-rhel8@sha256:4dbc9af138b09394f5b0e980f5844dd852dfa269f56061adbd6c071badbb3e7f
openshift-service-mesh/kiali-ossmc-rhel8@sha256:2abdbf22f8f99eb18dd3cb3393fd70e364a9e6a8348bb4028a2146a05b330a3a
openshift-service-mesh/kiali-rhel8@sha256:44ecbaac3a9f293c395a8bcf61bc09491934d425d0bc999afaca8f0a7f0225e7
openshift-service-mesh/pilot-rhel8@sha256:ffe5602bd1e2c9c2ad354f262cb130a89c11a0b48390155b7a7a670b16dbd9c3
openshift-service-mesh/proxyv2-rhel8@sha256:fcc3521fbb4be11baef5008353301dcec580045f003b12b7af3beb0107807fba
openshift-service-mesh/ratelimit-rhel8@sha256:4ca99e4ff0e5af748b818c93716e7172926d2552f80694aa0f1a9e0384f355d2

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:4005e591746c5febf32c236731bb0c26f70d019327bbdef42ca7cc963834b9ef
openshift-service-mesh/istio-cni-rhel8@sha256:d1aaffdf2037c27e617ecbc5b7d332f064d0835798eddf00a61e09506cc163f4
openshift-service-mesh/istio-must-gather-rhel8@sha256:bd74dd0c04d4d5787e2c3aafbca3d5712c2b100d1a320d544f924138c59740a0
openshift-service-mesh/kiali-ossmc-rhel8@sha256:119f5eadf591993b1fb4989f15b46e356f60a019256598e84523bd2bc08b6e3a
openshift-service-mesh/kiali-rhel8@sha256:a60f2267cd8adc02d3d726f009832f1348683b5d286eb895711f8cb6ab40d242
openshift-service-mesh/pilot-rhel8@sha256:fa1eb737072defb020f05061805a5c962b869bc34db82971a387958f1fb125af
openshift-service-mesh/proxyv2-rhel8@sha256:2233881311d88bd98a40a95af3131daa18fc5ac60290bf1c70f3b99488489118
openshift-service-mesh/ratelimit-rhel8@sha256:d7ba12eafd54c65fdd14a448d5fb5081a40c264911b39de3efc7b66ef0226ab3

s390x

openshift-service-mesh/grafana-rhel8@sha256:a540e7caea480f08a45b568d77143632f9037748d41f2e404acadb3e1c69993a
openshift-service-mesh/istio-cni-rhel8@sha256:2349b52f0eb89c430acac4652e16f6f87ccfdf729a2842c78e1d341289967cbd
openshift-service-mesh/istio-must-gather-rhel8@sha256:65468fe040df7e988286c888a9cb584a38fd52e0315e3d3baf880b0ff466e861
openshift-service-mesh/kiali-ossmc-rhel8@sha256:ba29942848135ede7214bd53ada5f4f27c2245c3832b26916f55f623ef5e0281
openshift-service-mesh/kiali-rhel8@sha256:9ace9ceea8337bbfab384d1f2080974eef24b3b88a58f104f2f4ab001cb8f16c
openshift-service-mesh/pilot-rhel8@sha256:9b975fe879ed990ff410a2cc72a6f1d7e49d63a86d5b4e90bf48eb6f6172d32d
openshift-service-mesh/proxyv2-rhel8@sha256:8581ad76cd8e4d17f36094bb65afffac23d47ecb5ade9590022466d44518bb59
openshift-service-mesh/ratelimit-rhel8@sha256:403318fb7177877f1a7075a76803b56d159cb6866a71c486c3d60de0eac73ea6

x86_64

openshift-service-mesh/grafana-rhel8@sha256:fddfbc8eb02901993de6b1e2e3ff300f2ed655e880913198db9625dd2bb2d901
openshift-service-mesh/istio-cni-rhel8@sha256:bcfe1c7fedf3ad05becc6feb4cc039e79ac8d96ba544e7d83a258208dea2a1c0
openshift-service-mesh/istio-must-gather-rhel8@sha256:e6fae53dd0b5126479293736486d73a7831150eb3ccef1e59fbd276340024c55
openshift-service-mesh/kiali-ossmc-rhel8@sha256:afda09c612d9eef60439a2ce29d5c0262abd63e33fc32aacf62e8aeaa88d42c4
openshift-service-mesh/kiali-rhel8@sha256:b9bc720b798b29639cc6563d64219ee19ff0b5f0ede40fe85df42db3333d2f8a
openshift-service-mesh/pilot-rhel8@sha256:23caccd0e422ac4b59397aa6d7a028f4df8a61488b7ea339d81cb8ac432c3716
openshift-service-mesh/proxyv2-rhel8@sha256:9d111abdce8928192a104a0fa4818f060aca5012c8c5107ff0fc489a594a16be
openshift-service-mesh/ratelimit-rhel8@sha256:bb8ff50a406cf719abb7d954a3ffcb7d3d7c73d21a5ed8bec9b994fcf93779cc

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility