Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Red Hat OpenShift Service Mesh Containers
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Red Hat OpenShift Service Mesh Containers
ID: RHSA-2025:3922
Distribution: Red Hat
Plattformen: Red Hat RHOSSM 2.5 for RHEL 8
Datum: Mi, 16. April 2025, 06:36
Referenzen: https://access.redhat.com/errata/RHSA-2025:3922
https://bugzilla.redhat.com/show_bug.cgi?id=2344219
https://access.redhat.com/security/cve/CVE-2025-22866
https://bugzilla.redhat.com/show_bug.cgi?id=2341751
https://access.redhat.com/security/cve/CVE-2024-45336
Applikationen: Red Hat OpenShift Service Mesh Containers

Originalnachricht

Red Hat OpenShift Service Mesh Containers for 2.5.10

This update has a security impact of Moderate. A Common Vulnerability Scoring
System (CVSS) base score, which gives a detailed severity rating, is available
for each vulnerability from the CVE link(s) in the References section.

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio
service
mesh project, tailored for installation into an OpenShift Container Platform
installation.

Security Fix(es):

* openshift-istio-kiali-rhel8-container: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
* openshift-istio-kiali-rhel8-container: Timing sidechannel for P-256 on
ppc64le in crypto/internal/nistec (CVE-2025-22866)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2024-45336: Exposure of Sensitive Information to an Unauthorized Actor
(CWE-200)
CVE-2025-22866: Exposure of Sensitive Information to an Unauthorized Actor
(CWE-200)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung