Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in Red Hat OpenShift Service Mesh
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in Red Hat OpenShift Service Mesh
ID: RHSA-2025:8298
Distribution: Red Hat
Plattformen: Red Hat OpenShift Service Mesh 3.0
Datum: Do, 29. Mai 2025, 22:40
Referenzen: https://access.redhat.com/errata/RHSA-2025:8298
https://access.redhat.com/security/cve/CVE-2025-22871
Applikationen: Red Hat OpenShift Service Mesh

Originalnachricht

Red Hat OpenShift Service Mesh 3.0.2
This update has a security impact of Moderate. A Common Vulnerability Scoring
System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section

Red Hat OpenShift Service Mesh 3.0.2, which is based on the open source Istio
project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application
Security Fix(es):
* openshift-istio-cni-container: Request smuggling due to acceptance of invalid
chunked data in net/http (CVE-2025-22871)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2025-22871: Inconsistent Interpretation of HTTP Requests ('HTTP
Request/Response Smuggling') (CWE-444)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung