The vendor explicitly identifies these products as affected by this CVE.
- rhacm2/acm-grafana-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- openshift4/topology-aware-lifecycle-manager-rhel8-operator as a component of Red Hat OpenShift Container Platform 4
- odf4/odf-multicluster-rhel8-operator as a component of Red Hat Openshift Data Foundation 4
- odf4/odr-rhel9-operator as a component of Red Hat Openshift Data Foundation 4
- Summary
- A flaw was found in the HashiCorp Consul package. In the affected versions of this package, a specially crafted CSR sent directly to Consul’s internal server agent RPC endpoint can include multiple SAN URI values with additional service names.
- Remediation
- Affected
