-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift Service Mesh 1.0.10 openshift-istio-kiali-rhel7-operator-container security update
Advisory ID:       RHSA-2020:0975-01
Product:           Red Hat OpenShift Service Mesh
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:0975
Issue date:        2020-03-25
CVE Names:         CVE-2020-1764 
====================================================================
1. Summary:

An update for openshift-istio-kiali-rhel7-operator-container is now
available for Openshift Service Mesh 1.0.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio
service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.

Security Fix(es):

* kiali: JWT cookie uses default signing key (CVE-2020-1764)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

The OpenShift Service Mesh release notes provide information on the
features and known issues:

https://docs.openshift.com/container-platform/4.3/service_mesh/v1x/servicemesh-release-notes.html

4. Bugs fixed (https://bugzilla.redhat.com/):

1810383 - CVE-2020-1764 kiali: JWT cookie uses default signing key

5. References:

https://access.redhat.com/security/cve/CVE-2020-1764
https://access.redhat.com/security/updates/classification/#moderate

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXnveetzjgjWX9erEAQgeKg/6AzBegVBolj0ldI0U4HpvQdqZebUrPOWZ
OtRL0qY9+nKnlkAgPphFnDGTAWUdbws+Q6ldLsoz4zH2fmWUgIwvpsTjPNwy8NhI
mpy1iX+HiUpE821dZBZSRX7sfYR6KzeeQZ8h4h/AzkzZgiXOdsafTK5JW59QXu52
Dd0mwtfW1qKnUbAvWIQtzxcfptuL/wWKlFvhW8Jt7ZuVyb3cudZ2qL+i+vb0F1KG
V5RKdtqYY7iZsYg/CbQBM9Vp9ng7OGvIT7xR9fGbokwGaWIlPUQpMVhzNNHrJOmq
zkYqiInNu7Fkf23n5ss82KiS2eymX0sEmZaLMRSXRCeL40/nZUZCm1QSI4bSyPv+
jfiKyosnyIKQNcGg8Wx359y0EPfG/FozEi1dlUAemfbIjAu54eAv/QeMhe+rHlKg
7Xb3/N2prbWHf+iufPuCwsPpIaORkhgBUoME8X5+fYkvJWCPl4YAVmQhgRXcRQGo
LtKwbkxLZEwwi2iEGOjP5oaa/18xCSNBSx5p87SfK2Naqio+L3b8/SS+GXX4fNC7
Oh/V72sn4CrKL9w97PC/W+ENL6mNTY7gQ1rBRsZfDY2R/d3RtCmX6JTZE9C3QaLJ
4mpDmIIePBcu7bSaf3pSiuJq5VFI7YK8G7WFQYb4+m8WWbxp5qkxB7YNZ7hGYvcT
bxD5PKUYiEc=S/sR
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-0975:01 Moderate: Red Hat OpenShift Service Mesh 1.0.10

An update for openshift-istio-kiali-rhel7-operator-container is now available for Openshift Service Mesh 1.0

Summary

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* kiali: JWT cookie uses default signing key (CVE-2020-1764)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

The OpenShift Service Mesh release notes provide information on the features and known issues:
https://docs.openshift.com/container-platform/4.3/service_mesh/v1x/servicemesh-release-notes.html

References

https://access.redhat.com/security/cve/CVE-2020-1764 https://access.redhat.com/security/updates/classification/#moderate

Package List


Severity
Advisory ID: RHSA-2020:0975-01
Product: Red Hat OpenShift Service Mesh
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0975
Issued Date: : 2020-03-25
CVE Names: CVE-2020-1764

Topic

An update for openshift-istio-kiali-rhel7-operator-container is nowavailable for Openshift Service Mesh 1.0.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1810383 - CVE-2020-1764 kiali: JWT cookie uses default signing key


Related News