The vendor explicitly identifies these products as affected by this CVE.
- rh-dotnet60-aspnetcore-runtime-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-aspnetcore-targeting-pack-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-apphost-pack-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-host as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-hostfxr-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-runtime-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-sdk-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-sdk-6.0-source-built-artifacts as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-targeting-pack-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet-templates-6.0 as a component of .NET 6.0 on Red Hat Enterprise Linux
- rh-dotnet60-dotnet.src as a component of .NET 6.0 on Red Hat Enterprise Linux
- Summary
- A flaw was found in the `got` package for node.js. Requested URLs are not verified and allow open redirection to a local UNIX socket.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
