Hide Forgot
It was found that the original fix for netty-codec-http CVE-2021-21409 in the OpenShift Logging elasticsearch6 container was incomplete, as the vulnerable netty-codec-http maven package was not removed from the image content.
This issue has been addressed in the following products: OpenShift Logging 5.3 Via RHSA-2022:0721 https://access.redhat.com/errata/RHSA-2022:0721
This issue has been addressed in the following products: OpenShift Logging 5.1 Via RHSA-2022:0727 https://access.redhat.com/errata/RHSA-2022:0727
This issue has been addressed in the following products: OpenShift Logging 5.2 Via RHSA-2022:0728 https://access.redhat.com/errata/RHSA-2022:0728
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-0552
This vulnerability has been addressed by this upstream commits: [https://github.com/ViaQ/elasticsearch/releases/tag/elasticsearch-oss-6.8.1.redhat-00019] [https://github.com/ViaQ/security/releases/tag/opendistro_security-0.10.1.2-redhat-00009] [https://github.com/openshift/origin-aggregated-logging/commit/d6b72d6c32e7c06b65324294d10406546734004d]