The vendor explicitly identifies these products as affected by this CVE.
- servicemesh-grafana as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.1
- css-what as a component of Red Hat build of Apicurio Registry 2
- css-what as a component of Red Hat Decision Manager 7
- css-what as a component of Red Hat Fuse 7
- css-what as a component of Red Hat Integration Service Registry
- css-what as a component of Red Hat JBoss Data Grid 7
- css-what as a component of Red Hat JBoss Enterprise Application Platform 6
- openshift3/ose-console as a component of Red Hat OpenShift Container Platform 3.11
- Summary
- A vulnerability was found in the css-what package. The flaw allows Regular expression denial of service (ReDoS) attacks, affecting system availability.
- Remediation
- Affected
