The vendor explicitly identifies these products as affected by this CVE.
- ocs4/cephcsi-rhel8 as a component of Red Hat Openshift Container Storage 4
- ocs4/mcg-rhel8-operator as a component of Red Hat Openshift Container Storage 4
- ocs4/ocs-rhel8-operator as a component of Red Hat Openshift Container Storage 4
- ocs4/rook-ceph-rhel8-operator as a component of Red Hat Openshift Container Storage 4
- odf4/mcg-rhel9-operator as a component of Red Hat Openshift Data Foundation 4
- Summary
- A flaw was found in HashiCorp Vault and Vault Enterprise. This issue could allow a remote authenticated attacker to bypass security restrictions, due to a flaw in the Google Cloud secrets engine when creating or updating rolesets. By sending a specially crafted request, an attacker could exploit this vulnerability to bypass the IAM policy.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
