RedHat: RHSA-2023-4625:01 Important: Red Hat OpenShift Service Mesh
Summary
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio
service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.
Security Fix(es):
* envoy: OAuth2 credentials exploit with permanent validity
(CVE-2023-35941)
* envoy: Incorrect handling of HTTP requests and responses with mixed case
schemes (CVE-2023-35944)
* envoy: CORS filter segfault when origin header is removed
(CVE-2023-35943)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Summary
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-35941 https://access.redhat.com/security/cve/CVE-2023-35943 https://access.redhat.com/security/cve/CVE-2023-35944 https://access.redhat.com/security/updates/classification/#important
Package List
Topic
Red Hat OpenShift Service Mesh 2.4.2 ContainersRed Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Bugs Fixed
2217977 - CVE-2023-35941 envoy: OAuth2 credentials exploit with permanent validity
2217985 - CVE-2023-35944 envoy: Incorrect handling of HTTP requests and responses with mixed case schemes
2217987 - CVE-2023-35943 envoy: CORS filter segfault when origin header is removed