The vendor explicitly identifies these products as affected by this CVE.
- openshift4/ose-grafana as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-prometheus as a component of Red Hat OpenShift Container Platform 4
- rhosdt/jaeger-all-in-one-rhel8 as a component of Red Hat OpenShift distributed tracing 2
- kubevirt-web-ui-container as a component of Red Hat OpenShift Virtualization 1
- nodejs-serialize-javascript.src as a component of Red Hat Quay 3
- Summary
- A flaw was found in the serialize-javascript before version 3.1.0. This flaw allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js."
- Remediation
- The OpenShift Service Mesh release notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/servicemesh-release-notes.html
