The vendor explicitly identifies these products as affected by this CVE.
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2.1
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2
- jszip as a component of Red Hat Fuse 7
- openshift3/ose-console as a component of Red Hat OpenShift Container Platform 3.11
- openshift4/ose-console-rhel9 as a component of Red Hat OpenShift Container Platform 4
- devspaces-theia-rhel8-container as a component of Red Hat OpenShift Dev Spaces
- quay/quay-rhel8 as a component of Red Hat Quay 3
- Summary
- A flaw was found in the JSZip package. Affected versions of JSZip could allow a remote attacker to traverse directories on the system caused by the failure to sanitize filenames when files are loaded with `loadAsync`, which makes the library vulnerable to a Zip Slip attack. By extracting files from a specially crafted archive, an attacker could gain access to parts of the file system outside of the target folder, overwrite the executable files, and execute arbitrary commands on the system.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
