|
| 1 | +[id="cluster-logging-release-notes-5-0-3"] |
| 2 | += OpenShift Logging 5.0.3 |
| 3 | + |
| 4 | +This release includes link:https://access.redhat.com/errata/RHSA-2021:1515[RHSA-2021:1515 Security Advisory for Important OpenShift Logging Bug Fix Release (5.0.3)] |
| 5 | + |
| 6 | + |
| 7 | +[id="openshift-logging-5-0-3-security-fixes"] |
| 8 | +== Security fixes |
| 9 | + |
| 10 | +* jackson-databind: arbitrary code execution in slf4j-ext class (link:https://www.redhat.com/security/data/cve/CVE-2018-14718.html[*CVE-2018-14718*]) |
| 11 | +* jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes (link:https://www.redhat.com/security/data/cve/CVE-2018-14719.html[*CVE-2018-14719*]) |
| 12 | +* jackson-databind: exfiltration/XXE in some JDK classes (link:https://www.redhat.com/security/data/cve/CVE-2018-14720.html[*CVE-2018-14720*]) |
| 13 | +* jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class (link:https://www.redhat.com/security/data/cve/CVE-2018-14721.html[*CVE-2018-14721*]) |
| 14 | +* jackson-databind: improper polymorphic deserialization in axis2-transport-jms class (link:https://www.redhat.com/security/data/cve/CVE-2018-19360.html[*CVE-2018-19360*]) |
| 15 | +* jackson-databind: improper polymorphic deserialization in openjpa class (link:https://www.redhat.com/security/data/cve/CVE-2018-19361.html[*CVE-2018-19361*]) |
| 16 | +* jackson-databind: improper polymorphic deserialization in jboss-common-core class (link:https://www.redhat.com/security/data/cve/CVE-2018-19362.html[*CVE-2018-19362*]) |
| 17 | +* jackson-databind: default typing mishandling leading to remote code execution (link:https://www.redhat.com/security/data/cve/CVE-2019-14379.htmld[*CVE-2019-14379*]) |
| 18 | +* jackson-databind: serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration (link:https://www.redhat.com/security/data/cve/CVE-2020-24750.html[*CVE-2020-24750*]) |
| 19 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource (link:https://www.redhat.com/security/data/cve/CVE-2020-35490.html[*CVE-2020-35490*]) |
| 20 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource (link:https://www.redhat.com/security/data/cve/CVE-2020-35491.html[*CVE-2020-35491*]) |
| 21 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (link:https://www.redhat.com/security/data/cve/CVE-2020-35728.html[*CVE-2020-35728*]) |
| 22 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS (link:https://www.redhat.com/security/data/cve/CVE-2020-36179.html[*CVE-2020-36179*]) |
| 23 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS (link:https://www.redhat.com/security/data/cve/CVE-2020-36180.html[*CVE-2020-36180*]) |
| 24 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS (link:https://www.redhat.com/security/data/cve/CVE-2020-36181.html[*CVE-2020-36181*]) |
| 25 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS (link:https://www.redhat.com/security/data/cve/CVE-2020-36182.html[*CVE-2020-36182*]) |
| 26 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool (link:https://www.redhat.com/security/data/cve/CVE-2020-36183.html[*CVE-2020-36183*]) |
| 27 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource (link:https://www.redhat.com/security/data/cve/CVE-2020-36184.html[*CVE-2020-36184*]) |
| 28 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource (link:https://www.redhat.com/security/data/cve/CVE-2020-36185.html[*CVE-2020-36185*]) |
| 29 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource (link:https://www.redhat.com/security/data/cve/CVE-2020-36186.html[*CVE-2020-36186*]) |
| 30 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource (link:https://www.redhat.com/security/data/cve/CVE-2020-36187.html[*CVE-2020-36187*]) |
| 31 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource (link:https://www.redhat.com/security/data/cve/CVE-2020-36188.html[*CVE-2020-36188*]) |
| 32 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource (link:https://www.redhat.com/security/data/cve/CVE-2020-36189.html[*CVE-2020-36189*]) |
| 33 | +* jackson-databind: mishandles the interaction between serialization gadgets and typing, related to javax.swing (link:https://www.redhat.com/security/data/cve/CVE-2021-20190.html[*CVE-2021-20190*]) |
| 34 | +* golang: data race in certain net/http servers including ReverseProxy can lead to DoS (link:https://www.redhat.com/security/data/cve/CVE-2020-15586.html[*CVE-2020-15586*]) |
| 35 | +* golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (link:https://www.redhat.com/security/data/cve/CVE-2020-16845.html[*CVE-2020-16845*]) |
| 36 | +* OpenJDK: Incomplete enforcement of JAR signing disabled algorithms (Libraries, 8249906) (link:https://www.redhat.com/security/data/cve/CVE-2021-2163.html[*CVE-2021-2163*]) |
| 37 | + |
| 38 | +The following Jira issues contain the above CVEs: |
| 39 | + |
| 40 | +* LOG-1234 CVE-2020-15586 CVE-2020-16845 openshift-eventrouter: various flaws [openshift-4]. (link:https://issues.redhat.com/browse/LOG-1234[*LOG-1234*]) |
| 41 | +* LOG-1243 CVE-2018-14718 CVE-2018-14719 CVE-2018-14720 CVE-2018-14721 CVE-2018-19360 CVE-2018-19361 CVE-2018-19362 CVE-2019-14379 CVE-2020-35490 CVE-2020-35491 CVE-2020-35728... logging-elasticsearch6-container: various flaws [openshift-logging-5.0]. (link:https://issues.redhat.com/browse/LOG-1243[*LOG-1243*]) |
| 42 | + |
| 43 | +[id="openshift-logging-5-0-3-bug-fixes"] |
| 44 | +== Bug fixes |
| 45 | + |
| 46 | +This release also includes the following bug fixes: |
| 47 | + |
| 48 | +* LOG-1224 Release 5.0 - ClusterLogForwarder namespace-specific log forwarding does not work as expected. (link:https://issues.redhat.com/browse/LOG-1224[*LOG-1224*]) |
| 49 | +* LOG-1232 5.0 - Bug 1859004 - Sometimes the eventrouter couldn't gather event logs. (link:https://issues.redhat.com/browse/LOG-1232[*LOG-1232*]) |
| 50 | +* LOG-1299 Release 5.0 - Forwarding logs to Kafka using Chained certificates fails with error "state=error: certificate verify failed (unable to get local issuer certificate)". (link:https://issues.redhat.com/browse/LOG-1299[*LOG-1299*]) |
0 commit comments