The vendor explicitly identifies these products as affected by this CVE.
- pkg as a component of Red Hat JBoss Enterprise Application Platform 6
- ocs4/mcg-core-rhel8 as a component of Red Hat Openshift Container Storage 4
- Summary
- An incorrect default permissions vulnerability was found in pkg. This issue allows an attacker who has access to the /tmp/pkg/ on the local system to replace the genuine executables in the shared directory with malicious executables of the same name.
- Remediation
- Out of support scope
