ZeroHour

CVE-2022-0552

CVSS 3.1
5.9 medium
EPSS
1%p66
Published
()
Modified
Description

A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.

Vendors
redhat
Products
origin-aggregated-logging
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.