The vendor explicitly identifies these products as affected by this CVE.
- distributed-tracing/jaeger-all-in-one-rhel7 as a component of Distributed Tracing Jaeger 1
- distributed-tracing/jaeger-query-rhel7 as a component of Distributed Tracing Jaeger 1
- nodejs-ua-parser-js.src as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- kibana as a component of Red Hat OpenShift Container Platform 3.11
- kibana.src as a component of Red Hat OpenShift Container Platform 3.11
- kibana as a component of Red Hat OpenShift Container Platform 4
- kibana.src as a component of Red Hat OpenShift Container Platform 4
- openshift4/ose-logging-kibana6 as a component of Red Hat OpenShift Container Platform 4
- grafana as a component of Red Hat Storage 3
- grafana.src as a component of Red Hat Storage 3
- Summary
- A flaw was found in nodejs-ua-parser-js. The software is vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891
