The vendor explicitly identifies these products as affected by this CVE.
- redhat-user-workloads/appliance as a component of Assisted Installer for Red Hat OpenShift Container Platform 2
- redhat-user-workloads/openshift-builds-waiter-1-6 as a component of Builds for Red Hat OpenShift
- redhat-user-workloads/openshift-builds-waiter-1-7 as a component of Builds for Red Hat OpenShift
- redhat-user-workloads/jetstack-cert-manager-1-17 as a component of cert-manager Operator for Red Hat OpenShift
- redhat-user-workloads/jetstack-cert-manager-1-18 as a component of cert-manager Operator for Red Hat OpenShift
- redhat-user-workloads/compliance-operator-bundle-release as a component of Compliance Operator
- redhat-user-workloads/osc-caa as a component of Confidential Compute Attestation
- redhat-user-workloads/trustee-operator as a component of Confidential Compute Attestation
- cryostat/cryostat-storage-rhel9 as a component of Cryostat 4
- redhat-user-workloads/keda-adapter as a component of Custom Metric Autoscaler operator for Red Hat Openshift
- redhat-user-workloads/deployment-validation-operator as a component of Deployment Validation Operator
- external-secrets-operator/external-secrets-rhel9 as a component of External Secrets Operator for Red Hat OpenShift
- Summary
- A flaw was found in the `html/template` package. This vulnerability arises from improper tracking of context and brace depth within JavaScript (JS) template literals. A remote attacker could exploit these issues to cause content to be incorrectly or improperly escaped, leading to Cross-Site Scripting (XSS) vulnerabilities. This could allow an attacker to inject malicious scripts into web pages viewed by other users.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
