drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Fehlerhafte Zugriffsrechte in mesh-operator
Name: |
Fehlerhafte Zugriffsrechte in mesh-operator |
|
ID: |
RHSA-2021:2380-01 |
|
Distribution: |
Red Hat |
|
Plattformen: |
Red Hat OpenShift Service Mesh |
|
Datum: |
Do, 10. Juni 2021, 23:16 |
|
Referenzen: |
https://access.redhat.com/security/cve/CVE-2021-3586 |
|
Applikationen: |
mesh-operator |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
===================================================================== Red Hat Security Advisory
Synopsis: Important: servicemesh-operator security update Advisory ID: RHSA-2021:2380-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2021:2380 Issue date: 2021-06-10 CVE Names: CVE-2021-3586 =====================================================================
1. Summary:
An update for servicemesh-operator is now available for OpenShift Service Mesh 2.0.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
2. Relevant releases/architectures:
2.0 - ppc64le, s390x, x86_64
3. Description:
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* servicemesh-operator: NetworkPolicy resources incorrectly specify ports for ingress resources (CVE-2021-3586)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
4. Solution:
The OpenShift Service Mesh Release Notes provide information on the features and known issues:
https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servi cemesh-release-notes.html
5. Bugs fixed (https://bugzilla.redhat.com/):
1967738 - CVE-2021-3586 servicemesh-operator: NetworkPolicy resources incorrectly specify ports for ingress resources
6. Package List:
2.0:
Source: servicemesh-operator-2.0.5-3.el8.src.rpm
ppc64le: servicemesh-operator-2.0.5-3.el8.ppc64le.rpm
s390x: servicemesh-operator-2.0.5-3.el8.s390x.rpm
x86_64: servicemesh-operator-2.0.5-3.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-3586 https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIVAwUBYMI/C9zjgjWX9erEAQgx6hAAp37ewWAO16MlS7MP1dPWu4izg68bE7pb 6Q+P+EhL4N6kXHyAp3fcZZgZ8aKad/1IjASNkhaUZJy5lffbX8MFM/kPytK8K0GH mj6yz/wzkLFKfsB9BPcM14pS4EB9WFm35sbSmAtLSW9vFqfpR+L43w5JLMxAiZ+M /cv+uzHph6TT3u1oAPKD7HdzWdE0gRslyTk96c816ruzmyoOSPNm4kLpahsU9lQC R5dt2G+0aOi15d6zIEKkf9n69GCdCoTnN/EnxE8eMqHCXTJttQANkEUg7egF1Qle 0PVrZ6Gg71dMDygVcmcnJ/o/unBRBy4KZYdd0HZ7LLvEXJ8U6EeswubNlIjYD+cj fWrFG3fuwNez+DmNut7DEflN8JNVmMdztcgZqBEYdfKRz2mjs3zGiVHjqruODArU khu5s1dfUcScZSaACbUiE2A8DI9KA4vbp0iJxH82x49LmzzFdjKFYcczqDS/T6cI hqGjHBBg0WqLhGQZbEYJi5Mu80C6R7UOyg0SF5DD4p5wwNI45dFwpfls5GrehJZO i/b9KMGXqkUrODM+NU4tSJiiJqoI4P5D/W9TLo0vOCZMfcsOOnPNmRu3n9mjrrt/ Ckw/KUALiz5ruLRa6bmN4QNBzgvKhTVlyIpc73FlX+SVofHSeK9RASfbpefGvTZx G/Ol34mgkX4= =J5gL -----END PGP SIGNATURE-----
-- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce
|
|
|
|