The vendor explicitly identifies these products as affected by this CVE.
- parse-url as a component of Red Hat Decision Manager 7
- openshift4/ose-console-rhel9 as a component of Red Hat OpenShift Container Platform 4
- rhosdt/jaeger-all-in-one-rhel8 as a component of Red Hat OpenShift distributed tracing 2
- rhosdt/jaeger-query-rhel8 as a component of Red Hat OpenShift distributed tracing 2
- openshift-gitops-1/argocd-rhel8 as a component of Red Hat OpenShift GitOps
- parse-url as a component of Red Hat Process Automation 7
- quay/quay-rhel8 as a component of Red Hat Quay 3
- Summary
- A cross-site-scripting (XSS) flaw was found in the parse-url package of npm. This issue could allow an attacker to use escape characters to run malicious JavaScript code on a webpage that was generated by the affected package. The highest impact is to integrity and confidentiality.
- Remediation
- Affected
