The vendor explicitly identifies these products as affected by this CVE.
- openshift4/ose-installer as a component of Red Hat OpenShift Container Platform 4
- openshift4/topology-aware-lifecycle-manager-rhel8-operator as a component of Red Hat OpenShift Container Platform 4
- ocs4/cephcsi-rhel8 as a component of Red Hat Openshift Container Storage 4
- ocs4/mcg-rhel8-operator as a component of Red Hat Openshift Container Storage 4
- ocs4/ocs-rhel8-operator as a component of Red Hat Openshift Container Storage 4
- ocs4/rook-ceph-rhel8-operator as a component of Red Hat Openshift Container Storage 4
- Summary
- A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the previous authenticated user’s cached secrets, even if they were not authorized by Vault policies to view them.
- Remediation
- Out of support scope
