The vendor explicitly identifies these products as affected by this CVE.
- multicluster-engine/console-mce-rhel8 as a component of Multicluster Engine for Kubernetes
- openshift-pipelines/pipelines-hub-db-migration-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines
- openshift-service-mesh/kiali-ossmc-rhel8 as a component of OpenShift Service Mesh 2
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2
- rhacm2/console-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- rhdh-operator-container as a component of Red Hat Developer Hub
- Summary
- A flaw was found in the Elliptic Node.js package. In certain versions, the ECDSA implementation does not correctly verify valid signatures if the hash contains at least 4 leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash. This issue can lead to valid signatures being rejected and a potential service disruption.
- Remediation
- Fix deferred
