The vendor explicitly identifies these products as affected by this CVE.
- openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines
- elliptic as a component of OpenShift Serverless
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2
- firefox as a component of Red Hat Enterprise Linux 6
- firefox.src as a component of Red Hat Enterprise Linux 6
- thunderbird as a component of Red Hat Enterprise Linux 6
- thunderbird.src as a component of Red Hat Enterprise Linux 6
- thunderbird as a component of Red Hat Enterprise Linux 7
- thunderbird.src as a component of Red Hat Enterprise Linux 7
- grafana as a component of Red Hat Enterprise Linux 8
- grafana-azure-monitor as a component of Red Hat Enterprise Linux 8
- grafana-cloudwatch as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in the Elliptic NodeJS package where it fails to properly verify the leading bit for the R and S values used in the ECDSA signature. This issue may lead to a scenario where an attacker can modify the signature without the Elliptic library being able to properly reject it, causing data confidentiality issues.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
