{"id":34529,"date":"2022-12-08T20:18:45","date_gmt":"2022-12-08T17:18:45","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170162\/RHSA-2022-8781-01.txt"},"modified":"2022-12-11T10:11:29","modified_gmt":"2022-12-11T06:41:29","slug":"red-hat-security-advisory-2022-8781-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-8781-01\/","title":{"rendered":"Red Hat Security Advisory 2022-8781-01"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p>=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p>Synopsis: Moderate: Logging Subsystem 5.5.5 &#8211; Red Hat OpenShift security update<br \/>\nAdvisory ID: RHSA-2022:8781-01<br \/>\nProduct: Logging Subsystem for Red Hat OpenShift<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8781<br \/>\nIssue date: 2022-12-08<br \/>\nCVE Names: CVE-2016-3709 CVE-2020-35525 CVE-2020-35527<br \/>\nCVE-2020-36516 CVE-2020-36518 CVE-2020-36558<br \/>\nCVE-2021-3640 CVE-2021-30002 CVE-2022-0168<br \/>\nCVE-2022-0561 CVE-2022-0562 CVE-2022-0617<br \/>\nCVE-2022-0854 CVE-2022-0865 CVE-2022-0891<br \/>\nCVE-2022-0908 CVE-2022-0909 CVE-2022-0924<br \/>\nCVE-2022-1016 CVE-2022-1048 CVE-2022-1055<br \/>\nCVE-2022-1184 CVE-2022-1292 CVE-2022-1304<br \/>\nCVE-2022-1355 CVE-2022-1586 CVE-2022-1785<br \/>\nCVE-2022-1852 CVE-2022-1897 CVE-2022-1927<br \/>\nCVE-2022-2068 CVE-2022-2078 CVE-2022-2097<br \/>\nCVE-2022-2509 CVE-2022-2586 CVE-2022-2639<br \/>\nCVE-2022-2879 CVE-2022-2880 CVE-2022-2938<br \/>\nCVE-2022-3515 CVE-2022-20368 CVE-2022-21499<br \/>\nCVE-2022-21618 CVE-2022-21619 CVE-2022-21624<br \/>\nCVE-2022-21626 CVE-2022-21628 CVE-2022-22624<br \/>\nCVE-2022-22628 CVE-2022-22629 CVE-2022-22662<br \/>\nCVE-2022-22844 CVE-2022-23960 CVE-2022-24448<br \/>\nCVE-2022-25255 CVE-2022-26373 CVE-2022-26700<br \/>\nCVE-2022-26709 CVE-2022-26710 CVE-2022-26716<br \/>\nCVE-2022-26717 CVE-2022-26719 CVE-2022-27404<br \/>\nCVE-2022-27405 CVE-2022-27406 CVE-2022-27664<br \/>\nCVE-2022-27950 CVE-2022-28390 CVE-2022-28893<br \/>\nCVE-2022-29581 CVE-2022-30293 CVE-2022-32189<br \/>\nCVE-2022-34903 CVE-2022-36946 CVE-2022-37434<br \/>\nCVE-2022-37603 CVE-2022-39399 CVE-2022-41715<br \/>\nCVE-2022-42003 CVE-2022-42004<br \/>\n=====================================================================<\/p>\n<p>1. Summary:<\/p>\n<p>Logging Subsystem 5.5.5 &#8211; Red Hat OpenShift<\/p>\n<p>Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p>2. Description:<\/p>\n<p>Logging Subsystem 5.5.5 &#8211; Red Hat OpenShift<\/p>\n<p>Security Fixe(s):<\/p>\n<p>* jackson-databind: denial of service via a large depth of nested<br \/>\nobjects (CVE-2020-36518)<\/p>\n<p>* golang: net\/http: handle server errors after sending GOAWAY<br \/>\n(CVE-2022-27664)<\/p>\n<p>* golang: archive\/tar: unbounded memory consumption when reading headers<br \/>\n(CVE-2022-2879, CVE-2022-2880, CVE-2022-41715)<\/p>\n<p>* jackson-databind: deep wrapper array nesting wrt<br \/>\nUNWRAP_SINGLE_VALUE_ARRAYS (CVE-2022-42003)<\/p>\n<p>* jackson-databind: use of deeply nested arrays (CVE-2022-42004)<\/p>\n<p>* loader-utils: Regular expression denial of service (CVE-2022-37603)<\/p>\n<p>* golang: math\/big: decoding big.Float and big.Rat types can panic if the<br \/>\nencoded message is too short, potentially allowing a denial of service<br \/>\n(CVE-2022-32189)<\/p>\n<p>For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p>3. Solution:<\/p>\n<p>For OpenShift Container Platform 4.11 see the following documentation,<br \/>\nwhich will be updated shortly for this release, for important instructions<br \/>\non how to upgrade your cluster and fully apply this errata update:<\/p>\n<p>https:\/\/docs.openshift.com\/container-platform\/4.11\/release_notes\/ocp-4-11-release-notes.html<\/p>\n<p>For Red Hat OpenShift Logging 5.5, see the following instructions to apply<br \/>\nthis update:<\/p>\n<p>https:\/\/docs.openshift.com\/container-platform\/4.11\/logging\/cluster-logging-upgrading.html<\/p>\n<p>4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p>2064698 &#8211; CVE-2020-36518 jackson-databind: denial of service via a large depth of nested objects<br \/>\n2113814 &#8211; CVE-2022-32189 golang: math\/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service<br \/>\n2124669 &#8211; CVE-2022-27664 golang: net\/http: handle server errors after sending GOAWAY<br \/>\n2132867 &#8211; CVE-2022-2879 golang: archive\/tar: unbounded memory consumption when reading headers<br \/>\n2132868 &#8211; CVE-2022-2880 golang: net\/http\/httputil: ReverseProxy should not forward unparseable query parameters<br \/>\n2132872 &#8211; CVE-2022-41715 golang: regexp\/syntax: limit memory used by parsing regexps<br \/>\n2135244 &#8211; CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS<br \/>\n2135247 &#8211; CVE-2022-42004 jackson-databind: use of deeply nested arrays<br \/>\n2140597 &#8211; CVE-2022-37603 loader-utils:Regular expression denial of service<\/p>\n<p>5. JIRA issues fixed (https:\/\/issues.jboss.org\/):<\/p>\n<p>LOG-2860 &#8211; Error on LokiStack Components when forwarding logs to Loki on proxy cluster<br \/>\nLOG-3131 &#8211; vector: kube API server certificate validation failure due to hostname mismatch<br \/>\nLOG-3222 &#8211; [release-5.5] fluentd plugin for kafka ca-bundle secret doesn&#8217;t support multiple CAs<br \/>\nLOG-3226 &#8211; FluentdQueueLengthIncreasing rule failing to be evaluated.<br \/>\nLOG-3284 &#8211; [release-5.5][Vector] logs parsed into structured when json is set without structured types.<br \/>\nLOG-3287 &#8211; [release-5.5] Increase value of cluster-logging PriorityClass to move closer to system-cluster-critical value<br \/>\nLOG-3301 &#8211; [release-5.5][ClusterLogging] elasticsearchStatus in ClusterLogging instance CR is not updated when Elasticsearch status is changed<br \/>\nLOG-3305 &#8211; [release-5.5] Kibana Authentication Exception cookie issue<br \/>\nLOG-3310 &#8211; [release-5.5] Can&#8217;t choose correct CA ConfigMap Key when creating lokistack in Console<br \/>\nLOG-3332 &#8211; [release-5.5] Reconcile error on controller when creating LokiStack with tls config<\/p>\n<p>6. References:<\/p>\n<p>https:\/\/access.redhat.com\/security\/cve\/CVE-2016-3709<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-35525<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-35527<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-36516<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-36518<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-36558<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3640<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-30002<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0168<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0561<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0562<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0617<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0854<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0865<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0891<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0908<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0909<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0924<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1016<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1048<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1055<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1184<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1292<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1304<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1355<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1586<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1785<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1852<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1897<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1927<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2068<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2078<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2097<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2509<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2586<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2639<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2879<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2880<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-2938<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-3515<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-20368<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21499<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21618<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21619<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21624<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21626<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21628<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22624<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22628<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22629<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22662<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22844<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-23960<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24448<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-25255<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26373<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26700<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26709<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26710<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26716<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26717<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-26719<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27404<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27405<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27406<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27664<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27950<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-28390<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-28893<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-29581<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-30293<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-32189<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-34903<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-36946<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-37434<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-37603<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-39399<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-41715<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-42003<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-42004<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p>7. Contact:<\/p>\n<p>The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p>Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p>iQIVAwUBY5G9q9zjgjWX9erEAQgdfBAApTzFp8Tp32Bv5jN1EnhSqzcQ93cUa2Nr<br \/>\not9YGh2Dzqr0lzAP2uf1O61EEYq9mte6X4DckjUDo7BT7u5ZZxMWWSstpNbFUzXl<br \/>\n4xs393yEZM52DN174XOP5V7GUG0pyNlEqHYMGjdZF6pzIx2zzF300kAjB4Hpg4wK<br \/>\nkKUDVnIyHlvlNcsvjms4p1rzAsIns4c73W89KVkwMyo1pvPQt6v34BWZg5DNnYAM<br \/>\nhTzl0JR5XRYW4aZhIMq7FApvh4GeA7n7L0kmnDHFVcx0cnrHrjHZxmRQX0Gai1bc<br \/>\nr8MvGvbMTqEAZ4VKKrgNVvVzkdrO4dw20JfbskPgTIbFXH6ns5605b31veRhMYmv<br \/>\nNCSJUbq4BLYVAZEhmLa0QIqru1WVCB1e2eRUhvehLiuVlAkgmIgtKvECZ3kpQHxj<br \/>\nDvOdnaWC5R9eKtNlX9N1xOtqgOF2w+\/M+5ml5RJgq48Wlb41VpypDIKFBUXh+wR9<br \/>\nArrG8kao75Hl0t8\/YQMouqDvgJLNgfceF+WETYryfDus9OlB4YMxhI88mx7HH9zu<br \/>\nHy4rb7RhF1OcH\/kWjmMl\/YJQpYSFKJDyls3tAx5ZAWGCpwAzoBZoc9BEKUQwVfnW<br \/>\nf3PFotJeQdxKBsbqKVF5h0gHcfSUP+P0kQhx1GD51kxJkUmq47m3OZKIe1QLwYgm<br \/>\nT1GSDHkQTcg=<br \/>\n=y\/FA<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Logging Subsystem 5.5.5 &#8211; Red Hat OpenShift security update Advisory ID: RHSA-2022:8781-01 Product: Logging Subsystem for Red Hat OpenShift Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:8781 Issue date: 2022-12-08 CVE Names: CVE-2016-3709 CVE-2020-35525 CVE-2020-35527 CVE-2020-36516 CVE-2020-36518 CVE-2020-36558 CVE-2021-3640 CVE-2021-30002 CVE-2022-0168 CVE-2022-0561 CVE-2022-0562 CVE-2022-0617 CVE-2022-0854 CVE-2022-0865 CVE-2022-0891 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34529","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34529"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34529\/revisions"}],"predecessor-version":[{"id":34684,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34529\/revisions\/34684"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}