The vendor explicitly identifies these products as affected by this CVE.
- openshift-logging/logging-loki-rhel9 as a component of Logging Subsystem for Red Hat OpenShift
- openshift4/topology-aware-lifecycle-manager-rhel8-operator as a component of Red Hat OpenShift Container Platform 4
- openshift4/topology-aware-lifecycle-operator-precache-rhel8 as a component of Red Hat OpenShift Container Platform 4
- odf4/odf-multicluster-rhel8-operator as a component of Red Hat Openshift Data Foundation 4
- odf4/odr-rhel9-operator as a component of Red Hat Openshift Data Foundation 4
- Summary
- A flaw was found in the Consul and Consul Enterprise (“Consul”) where HTTP health check endpoints return an HTTP redirect, which can be abused as a vector for server-side request forgery (SSRF).
- Remediation
- Affected
