Red Hat 8094 Published by

An Openshift Logging Security Release (5.0.10) has been released.

RHSA-2021:5137-03: Moderate: Openshift Logging Security Release (5.0.10)

Red Hat Security Advisory

Synopsis: Moderate: Openshift Logging Security Release (5.0.10)
Advisory ID: RHSA-2021:5137-01
Product: Red Hat OpenShift Enterprise
Advisory URL:
Issue date: 2021-12-14
CVE Names: CVE-2018-20673 CVE-2018-25009 CVE-2018-25010
CVE-2018-25012 CVE-2018-25013 CVE-2018-25014
CVE-2019-5827 CVE-2019-13750 CVE-2019-13751
CVE-2019-14615 CVE-2019-17594 CVE-2019-17595
CVE-2019-18218 CVE-2019-19603 CVE-2019-20838
CVE-2020-0427 CVE-2020-10001 CVE-2020-12762
CVE-2020-13435 CVE-2020-14145 CVE-2020-14155
CVE-2020-16135 CVE-2020-17541 CVE-2020-24370
CVE-2020-24502 CVE-2020-24503 CVE-2020-24504
CVE-2020-24586 CVE-2020-24587 CVE-2020-24588
CVE-2020-26139 CVE-2020-26140 CVE-2020-26141
CVE-2020-26143 CVE-2020-26144 CVE-2020-26145
CVE-2020-26146 CVE-2020-26147 CVE-2020-27777
CVE-2020-29368 CVE-2020-29660 CVE-2020-35448
CVE-2020-35521 CVE-2020-35522 CVE-2020-35523
CVE-2020-35524 CVE-2020-36158 CVE-2020-36312
CVE-2020-36330 CVE-2020-36331 CVE-2020-36332
CVE-2020-36386 CVE-2021-0129 CVE-2021-3200
CVE-2021-3348 CVE-2021-3426 CVE-2021-3445
CVE-2021-3481 CVE-2021-3487 CVE-2021-3489
CVE-2021-3564 CVE-2021-3572 CVE-2021-3573
CVE-2021-3580 CVE-2021-3600 CVE-2021-3635
CVE-2021-3659 CVE-2021-3679 CVE-2021-3712
CVE-2021-3732 CVE-2021-3778 CVE-2021-3796
CVE-2021-3800 CVE-2021-20194 CVE-2021-20197
CVE-2021-20231 CVE-2021-20232 CVE-2021-20239
CVE-2021-20266 CVE-2021-20284 CVE-2021-22876
CVE-2021-22898 CVE-2021-22925 CVE-2021-23133
CVE-2021-23840 CVE-2021-23841 CVE-2021-27645
CVE-2021-28153 CVE-2021-28950 CVE-2021-28971
CVE-2021-29155 CVE-2021-29646 CVE-2021-29650
CVE-2021-31440 CVE-2021-31535 CVE-2021-31829
CVE-2021-31916 CVE-2021-33033 CVE-2021-33200
CVE-2021-33560 CVE-2021-33574 CVE-2021-35942
CVE-2021-36084 CVE-2021-36085 CVE-2021-36086
CVE-2021-36087 CVE-2021-42574 CVE-2021-43527

1. Summary:

Openshift Logging Security Release (5.0.10)

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Openshift Logging Bug Fix Release (5.0.10)

Security Fix(es):

* log4j-core: Remote code execution in Log4j 2.x when logs contain an
attacker-controlled string value (CVE-2021-44228)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this errata update:

For Red Hat OpenShift Logging 5.0, see the following instructions to apply
this update:

4. Bugs fixed (

2030932 - CVE-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value

5. References:

6. Contact:

The Red Hat security contact is . More contact
details at

Copyright 2021 Red Hat, Inc.