The vendor explicitly identifies these products as affected by this CVE.
- io.cryostat-cryostat as a component of Cryostat 4
- openshift-pipelines/pipelines-hub-api-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-db-migration-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines
- 3scale-amp2/system-rhel7 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp2/system-rhel9 as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp20/system as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp21/system as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp22/system as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp24/system as a component of Red Hat 3scale API Management Platform 2
- 3scale-amp25/system as a component of Red Hat 3scale API Management Platform 2
- Summary
- A flaw was found in SVGO, an SVG (Scalable Vector Graphics) Optimizer. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by submitting a specially crafted XML file. The application's failure to properly guard against XML entity expansion or recursion can lead to the Node.js process consuming excessive memory and crashing.
- Remediation
- For details on how to apply this update, refer to Ansible Automation Platform documentation.
