Back

MEDIUM

origin-aggregated-logging/elasticsearch: Incomplete fix for netty-codec-http CVE-2021-21409

Published Apr 11, 2022

Description

A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.

Affected products

Remediation

Red Hat statement

This CVE only applies to the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container image, shipped in OpenShift Logging 5.1, 5.2. and 5.3. https://access.redhat.com/errata/RHSA-2021:5128 https://access.redhat.com/errata/RHSA-2021:5127 https://access.redhat.com/errata/RHSA-2021:5129

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 11, 2022
Updated Aug 2, 2024
Reserved Feb 9, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 28, 2022
ENISA EUVD
Assigner redhat
Published Apr 11, 2022
Updated Aug 2, 2024
Exploited since n/a
EUVD-2022-15674