The vendor explicitly identifies these products as affected by this CVE.
- ceph-base as a component of Red Hat Ceph Storage 7
- ceph-common as a component of Red Hat Ceph Storage 7
- ceph-fuse as a component of Red Hat Ceph Storage 7
- ceph-immutable-object-cache as a component of Red Hat Ceph Storage 7
- ceph-mib as a component of Red Hat Ceph Storage 7
- ceph-resource-agents as a component of Red Hat Ceph Storage 7
- ceph-selinux as a component of Red Hat Ceph Storage 7
- ceph.src as a component of Red Hat Ceph Storage 7
- cephadm as a component of Red Hat Ceph Storage 7
- cephfs-top as a component of Red Hat Ceph Storage 7
- libcephfs-devel as a component of Red Hat Ceph Storage 7
- libcephfs2 as a component of Red Hat Ceph Storage 7
- Summary
- taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB. However, it is found that the internal index can be forged by adding additional properties into user-input. If index is found in the query, taffyDB will ignore other query conditions and directly return the indexed data item. Moreover, the internal index is in an easily-guessable format (e.g., T000002R000001). As such, attackers can use this vulnerability to access any data items in the DB.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993
