Rapid7 Vulnerability & Exploit Database

Oracle Linux: (CVE-2022-29226) (Multiple Advisories): olcne security update

Back to Search

Oracle Linux: (CVE-2022-29226) (Multiple Advisories): olcne security update

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
06/09/2022
Created
07/16/2022
Added
07/12/2022
Modified
07/13/2022

Description

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the current implementation assumes that access tokens are always validated thus allowing access in the presence of any access token attached to the request. Users are advised to upgrade. There is no known workaround for this issue.

Solution(s)

  • oracle-linux-upgrade-cri-o
  • oracle-linux-upgrade-cri-tools
  • oracle-linux-upgrade-etcd
  • oracle-linux-upgrade-istio
  • oracle-linux-upgrade-istio-istioctl
  • oracle-linux-upgrade-kata
  • oracle-linux-upgrade-kubeadm
  • oracle-linux-upgrade-kubectl
  • oracle-linux-upgrade-kubelet
  • oracle-linux-upgrade-kubernetes
  • oracle-linux-upgrade-olcne
  • oracle-linux-upgrade-olcne-agent
  • oracle-linux-upgrade-olcne-api-server
  • oracle-linux-upgrade-olcne-gluster-chart
  • oracle-linux-upgrade-olcne-grafana-chart
  • oracle-linux-upgrade-olcne-istio-chart
  • oracle-linux-upgrade-olcne-metallb-chart
  • oracle-linux-upgrade-olcne-nginx
  • oracle-linux-upgrade-olcne-oci-ccm-chart
  • oracle-linux-upgrade-olcne-oci-csi-chart
  • oracle-linux-upgrade-olcne-olm-chart
  • oracle-linux-upgrade-olcne-prometheus-chart
  • oracle-linux-upgrade-olcne-utils
  • oracle-linux-upgrade-olcnectl

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;