The vendor explicitly identifies these products as affected by this CVE.
- uglify-js.src as a component of Migration Toolkit for Runtimes
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0
- servicemesh-prometheus as a component of OpenShift Service Mesh 2.0
- servicemesh-prometheus.src as a component of OpenShift Service Mesh 2.0
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana as a component of OpenShift Service Mesh 2.1
- servicemesh-grafana.src as a component of OpenShift Service Mesh 2.1
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2
- rhacm2/console-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A prototype pollution vulnerability was found in UglifyJS, stemming from the DEFNODE function in ast.js via the name variable. Exploiting this flaw involves adding or altering properties of the Object.prototype through a "__proto__" or constructor payload, enabling an attacker to execute arbitrary code or causing a denial of service on the system.
- Remediation
- Affected
