Red Hat Openshift Service Mesh -

CPE Details

Red Hat Openshift Service Mesh -
-
2021-12-27
11h51 +00:00
2022-06-06
11h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:openshift_service_mesh:-:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

openshift_service_mesh

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-1704 2020-02-17 15h38 +00:00 An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
7.8
High
CVE-2019-9900 2019-04-25 12h55 +00:00 When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
8.3
High