Medium severity5.9OSV Advisory· Published Apr 11, 2022· Updated Jun 17, 2026
CVE-2022-0552
CVE-2022-0552
Description
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 1.3.0-alpha.1, elasticsearch-6.8.1.redhat-00002, elasticsearch-oss-6.8.1.redhat-00006, …
cpe:2.3:a:redhat:origin-aggregated-logging:3.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:origin-aggregated-logging:3.11:*:*:*:*:*:*:*
- (no CPE)range: 3.11
- Range: 3.11
Patches
Vulnerability mechanics
References
3- github.com/openshift/origin-aggregated-logging/commit/d6b72d6c32e7c06b65324294d10406546734004dnvdPatchThird Party Advisory
- access.redhat.com/security/cve/CVE-2021-21409nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.