The vendor explicitly identifies these products as affected by this CVE.
- authorino-container as a component of Red Hat Connectivity Link 1
- rhosdt/tempo-gateway-opa-rhel8 as a component of Red Hat OpenShift distributed tracing 3
- Summary
- An SMB force-authentication vulnerability exists in all versions of OPA. The vulnerability exists due to improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or one of the OPA Go library’s functions.
- Remediation
- For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/h tml/operators/administrator-tasks#olm-upgrading-operators
