The vendor explicitly identifies these products as affected by this CVE.
- mta/mta-admin-addon-rhel8 as a component of Migration Toolkit for Applications 6
- mta/mta-windup-addon-rhel8 as a component of Migration Toolkit for Applications 6
- openshift-serverless-1/ingress-rhel8-operator as a component of OpenShift Serverless
- acm-multicluster-globalhub-agent-container as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- rhacm2/thanos-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- advanced-cluster-security/rhacs-main-rhel8 as a component of Red Hat Advanced Cluster Security 3
- advanced-cluster-security/rhacs-scanner-rhel8 as a component of Red Hat Advanced Cluster Security 3
- openshift4/ose-coredns-rhel9 as a component of Red Hat OpenShift Container Platform 4
- rhods/odh-ml-pipelines-cache-rhel8 as a component of Red Hat OpenShift Data Science (RHODS)
- devspaces/machineexec-rhel8 as a component of Red Hat OpenShift Dev Spaces
- openshift-gitops-1/argo-rollouts-rhel8 as a component of Red Hat OpenShift GitOps
- openshift-gitops-1/argocd-rhel8 as a component of Red Hat OpenShift GitOps
- Summary
- A flaw was found in the Gin-Gonic Gin Web Framework. Affected versions of this package could allow a remote attacker to bypass security restrictions caused by improper input validation by the filename parameter of the Context.FileAttachment function. An attacker can modify the Content-Disposition header by using a specially-crafted attachment file name.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
