VDB
RHSA-2022:1356
RHSA-2022:1356
PUBLISHED
CVSS 7.5 HIGH
A denial of service attack was found in prometheus/client_golang. This flaw allows an attacker to produce a denial of service attack on an HTTP server by exploiting the InstrumentHandlerCounter function in the version below 1.11.1, resulting in a loss of availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-cluster-cloud-controller-manager-operator-rhel8@sha256:a733e225fa0aff4b1c897ac46fed5b6b6b67d2d683ab0569785aea3f87b39fb6_s390x as a component of Red Hat OpenShift Container Platform 4.10 | *, openshift4/ose-cluster-cloud-controller-manager-operator-rhel8@sha256:a733e225fa0aff4b1c897ac46fed5b6b6b67d2d683ab0569785aea3f87b39fb6_s390x |
| Red Hat | openshift4/ose-insights-rhel8-operator@sha256:fcb024641e1fb932dbe8bcadc91ced95c2aa473a5a9168ec4db48052c5a342e9_arm64 as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-insights-rhel8-operator@sha256:fcb024641e1fb932dbe8bcadc91ced95c2aa473a5a9168ec4db48052c5a342e9_arm64, openshift4/ose-insights-rhel8-operator@sha256:fcb024641e1fb932dbe8bcadc91ced95c2aa473a5a9168ec4db48052c5a342e9_arm64 |
| Red Hat | openshift4/ose-csi-node-driver-registrar@sha256:1b0d6122926d9cbbe1274b38c55c96d95687e7c090adc3c7afd20c3b8bf3b4a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.10 | *, * |
| Red Hat | openshift4/ose-console-operator@sha256:6d5f5824f5dce2975724c5710a154c8449e599705526b3cf241d7364adfc9fd4_ppc64le as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-console-operator@sha256:6d5f5824f5dce2975724c5710a154c8449e599705526b3cf241d7364adfc9fd4_ppc64le, openshift4/ose-console-operator@sha256:6d5f5824f5dce2975724c5710a154c8449e599705526b3cf241d7364adfc9fd4_ppc64le |
| Red Hat | openshift4/ose-multus-admission-controller@sha256:53a6035edb3e7ed537d93314f801c665a32b932739202c6a692cab5d31bd21a8_amd64 as a component of Red Hat OpenShift Container Platform 4.10 | *, openshift4/ose-multus-admission-controller@sha256:53a6035edb3e7ed537d93314f801c665a32b932739202c6a692cab5d31bd21a8_amd64 |
| Red Hat | openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:4dc39756cf9d65121ee947682eec18d662a589b8b927217532eb9bf94b6e55db_s390x as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-cluster-csi-snapshot-controller-rhel8-operator@sha256:4dc39756cf9d65121ee947682eec18d662a589b8b927217532eb9bf94b6e55db_s390x, * |
| Red Hat | openshift4/ose-haproxy-router@sha256:cf6c61ab12d943c3008b315e67725922c4089c8e8e2009ad88424bbdaf852c19_s390x as a component of Red Hat OpenShift Container Platform 4.10 | *, * |
| Red Hat | openshift4/ose-thanos-rhel8@sha256:8e0ab60348bb82ced07f5034e500ceb3d107e1314cdf39dc807b23e0be8217c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-thanos-rhel8@sha256:8e0ab60348bb82ced07f5034e500ceb3d107e1314cdf39dc807b23e0be8217c2_ppc64le, * |
| Red Hat | openshift4/ose-openshift-state-metrics-rhel8@sha256:0e6f8247c19f17f34334afa7a10a2c895b0dfc021d37fefa71963e21e7eee2e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.10 | *, openshift4/ose-openshift-state-metrics-rhel8@sha256:0e6f8247c19f17f34334afa7a10a2c895b0dfc021d37fefa71963e21e7eee2e2_ppc64le |
| Red Hat | openshift4/ose-prometheus-node-exporter@sha256:3f276dab48846236f9f82cf5bc09564867199840b67de5aac1f11fdb8e95c4d0_amd64 as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-prometheus-node-exporter@sha256:3f276dab48846236f9f82cf5bc09564867199840b67de5aac1f11fdb8e95c4d0_amd64, * |
| Red Hat | openshift4/ose-csi-external-resizer@sha256:a639ff8d8380173956c8ec25186d2382f7d9eece795a9f913afb98d0f54ffa64_arm64 as a component of Red Hat OpenShift Container Platform 4.10 | *, * |
| Red Hat | openshift4/ose-kube-storage-version-migrator-rhel8@sha256:f5743217024afb850d4b72495958dafebc2542208794d481c575596988804fe9_ppc64le as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-kube-storage-version-migrator-rhel8@sha256:f5743217024afb850d4b72495958dafebc2542208794d481c575596988804fe9_ppc64le, * |
| Red Hat | openshift4/ose-installer@sha256:6f06c811c9144d839783d88d820f0ab4bc050b70f36ab149a9cf4e816216963d_amd64 as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-installer@sha256:6f06c811c9144d839783d88d820f0ab4bc050b70f36ab149a9cf4e816216963d_amd64, openshift4/ose-installer@sha256:6f06c811c9144d839783d88d820f0ab4bc050b70f36ab149a9cf4e816216963d_amd64 |
| Red Hat | openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:a5e6cb5581695afaaaa09c24c3b27c6294463a851b5534e35a18ceee752a2f73_arm64 as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:a5e6cb5581695afaaaa09c24c3b27c6294463a851b5534e35a18ceee752a2f73_arm64, * |
| Red Hat | openshift4/ose-service-ca-operator@sha256:a309fbdc31e29d50b473c325ab92d898c5f9e507f48898737d4e0984682eee8b_arm64 as a component of Red Hat OpenShift Container Platform 4.10 | *, openshift4/ose-service-ca-operator@sha256:a309fbdc31e29d50b473c325ab92d898c5f9e507f48898737d4e0984682eee8b_arm64 |
| Red Hat | openshift4/ose-csi-snapshot-controller@sha256:cfb1773327013daff7deb05a36a81eba7338e3e9d998df2f7f5de9bbde4d3f6a_s390x as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-csi-snapshot-controller@sha256:cfb1773327013daff7deb05a36a81eba7338e3e9d998df2f7f5de9bbde4d3f6a_s390x, openshift4/ose-csi-snapshot-controller@sha256:cfb1773327013daff7deb05a36a81eba7338e3e9d998df2f7f5de9bbde4d3f6a_s390x |
| Red Hat | openshift4/ose-csi-livenessprobe@sha256:67685139464b95ef55930048e4114af29e1a2d1bbbda7e34c4c551a9c4eebc13_ppc64le as a component of Red Hat OpenShift Container Platform 4.10 | *, openshift4/ose-csi-livenessprobe@sha256:67685139464b95ef55930048e4114af29e1a2d1bbbda7e34c4c551a9c4eebc13_ppc64le |
| Red Hat | openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:e0eeb2ac5f04bc44e3fd822c8e14bae4bdef5a09ed48033252999b4274d5ce10_amd64 as a component of Red Hat OpenShift Container Platform 4.10 | *, openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:e0eeb2ac5f04bc44e3fd822c8e14bae4bdef5a09ed48033252999b4274d5ce10_amd64 |
| Red Hat | openshift4/ose-cluster-dns-operator@sha256:edaebae22106ccccb7efa2484d4db557e92c93fbc948fe3ee191bef7583aafb7_amd64 as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-cluster-dns-operator@sha256:edaebae22106ccccb7efa2484d4db557e92c93fbc948fe3ee191bef7583aafb7_amd64, * |
| Red Hat | openshift4/ose-ovirt-machine-controllers-rhel8@sha256:a753cc51cec26978d9c26c3b60e9d3522c9c20fad2a583f06f19cafe5420418b_amd64 as a component of Red Hat OpenShift Container Platform 4.10 | openshift4/ose-ovirt-machine-controllers-rhel8@sha256:a753cc51cec26978d9c26c3b60e9d3522c9c20fad2a583f06f19cafe5420418b_amd64, * |
…and 1116 more
Timeline
- Apr 21, 2022 CVE Published
- Apr 25, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2054404 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2054808 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2055661 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2057881 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2059945 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2060586 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2064988 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2067311 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2069095 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2070492 issue
- https://www.cve.org/CVERecord?id=CVE-2022-21698 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2050118 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2052414 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2059347 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2067719 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2072191 issue
- https://access.redhat.com/security/cve/CVE-2022-21698 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-21698 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2054767 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2060362 issue
…and 14 more