Published severityHigh→Operational priority:High, unchanged from published severity.unchanged
Evidence used
No CISA KEV confirmation is currently recorded.
EPSS is 0.23% for the current model date.
Compensating controls
Validate the affected product branch and deploy the verified fixed release.
Restrict the affected network interface to trusted sources where business-safe.
Monitor vendor guidance and exploitation sources for a material change.
Verification
Confirm that the asset runs remix-run react-router and falls inside the recorded affected range.
Verify the installed build against the product-specific fixed version after deployment.
Validate exposure, authentication requirements and compensating controls in the actual environment.
Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Open-source package ranges1 source-attributed range
These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.
Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.
1 current
CVE-2026-33245 · CSAF 2.0 · revision 3 · finalRed Hat Product Securityreact-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects
155 known affected
The vendor explicitly identifies these products as affected by this CVE.
exploit-intelligence-tech-preview/agent-client-rhel9 as a component of Exploit Intelligence
gatekeeper/gatekeeper-rhel9 as a component of Gatekeeper 3
mta/mta-ui-rhel8 as a component of Migration Toolkit for Applications 8
mta/mta-ui-rhel9 as a component of Migration Toolkit for Applications 8
rhmtc/openshift-migration-ui-rhel8 as a component of Migration Toolkit for Containers
migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization
mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization
multicluster-engine/console-mce-rhel9 as a component of Multicluster Engine for Kubernetes
network-observability/network-observability-console-plugin-compat-rhel9 as a component of Network Observability Operator
network-observability/network-observability-console-plugin-rhel9 as a component of Network Observability Operator
workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator
workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator
Summary
A flaw was found in React Router. This vulnerability, a type of Cross-Site Scripting (XSS), affects applications utilizing React Router's unstable React Server Components (RSC) APIs. A remote attacker could exploit this by sending untrusted redirects, leading to the execution of malicious scripts in the client's browser. This could result in information disclosure or unauthorized actions.
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Optional official sources
National CERT insights ?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.
Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.
Official European source
ENISA European Vulnerability Database
Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.
1 current
ENISA EUVD identifier
EUVD-2026-33988
No EUVD known-exploited evidence
ENISA has published the identifier mapping but no EUVD description has been stored yet.
EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days
High technical severity; prioritise exposed affected systems while verifying vendor guidance.
Patch available
01
What, why and how
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
What
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Why
Attacker-controlled content can reach a browser as executable script without sufficient output encoding or sanitisation.
How
An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
What
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Why
Attacker-controlled content can reach a browser as executable script without sufficient output encoding or sanitisation.
How
An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
02
Exploit reality and attack path
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
Observed exploitation ?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.No confirmed evidence
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
Public PoC / exploit material ?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.None recorded
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
Likely attack path
a network path → Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
Required interaction required
Attack complexity
High: exploitation depends on specific conditions
Security boundary
Changed: exploitation can affect a different security authority
Weakness ?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVSS vector ?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
AVNetworkAttack vector: The vulnerable component can be reached over a network.ACHighAttack complexity: Successful exploitation depends on specific conditions outside the attacker's direct control.PRNonePrivileges required: The attacker does not need an account or existing privileges.UIRequiredUser interaction: Another user must perform an action for exploitation to succeed.SChangedScope: The attack can affect a component governed by a different security authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-79
A
Official authority intelligence
Only matched European and national findings are included. Language selectors and unavailable sources are omitted.
ENISA EUVD · EUVD-2026-33988Official EUVD mapping
0 linked advisory records.
Official EUVD record ↗CERT-FR · French · CERTFR-2026-AVI-0933Multiples vulnérabilités dans les produits IBM
Operational remediation based on structured source evidence.
Status ?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04
Evidence and provenance
Published 2 Jun 2026 · Last source change 3 Jun 2026, 19:09 UTC · CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE recordCVE.org · 5.2
CVSS sourceCNA
EPSS source ?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2026-33988
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceCNA
NVD statusNVD enriched
Core structured fields are present and their contributing authorities are shown above.
Affected versionsThe structured affected or fixed version information changed.
Before
exploit-intelligence-tech-preview/agent-client-rhel9 as a component of Exploit Intelligence; gatekeeper/gatekeeper-rhel9 as a component of Gatekeeper 3; mta/mta-ui-rhel8 as a component of Migration Toolkit for Applications 8; mta/mta-ui-rhel9 as a component of Migration Toolkit for Applications 8; rhmtc/openshift-migration-ui-rhel8 as a component of Migration Toolkit for Containers; migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; multicluster-engine/console-mce-rhel9 as a component of Multicluster Engine for Kubernetes; network-observability/network-observability-console-plugin-compat-rhel9 as a component of Network Observability Operator; network-observability/network-observability-console-plugin-rhel9 as a component of Network Observability Operator; workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-rhel9-operator as a component of Node HealthCheck Operator; openshift-lightspeed/lightspeed-console-plugin-419-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed; openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines; openshift-service-mesh/kiali-ossmc-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-operator-bundle as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-ossmc-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9-operator as a component of OpenShift Service Mesh 3; redhat-user-workloads/console-acm-211 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/console-acm-212 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/console-acm-213 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; and 125 more · Fixed: Red Hat Data Grid 8.6.2; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3a33448671868e7f6eb540a9adf1d0b544064f8494c6acdbaac2e6c9f49c4482_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5fdb1f33e2811ec60610b00f3c2dbadfd9673aa23969c5b2e6be495da9325cc2_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:b4a5fa8fb4a9f7f07f922b5d4aa92b9be30c9a2a905ca295e91be40b8a1f7b19_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f31bef6afba629e3c71da48e40c3e3f969589d38a6cefe28094cb962d7fc960e_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:0a3300adf425bc30ba99d2771948e08b571d239a852436438801756f741fbf5a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:19395e8f07e6ed991317764bbd47ecada91719fea7cc79e2eb853426168c5fc7_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:24babc0af3dd8dd8588f91e72273ea148d3d58ab4de7ed4c45bf9e128a1028f8_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:f7b6fe3439bd36d31e7bcbe72180d63a4976943b54046fff86e393f49d2c71b6_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:0e8e3d0d3c979f9faffa203a2c50629744d9919505c090e3003603557c4c49dd_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:9313f8478a794e84f4ee58eb5543d94ab8597a224dc41acd17ee513ea95d39eb_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:cb7077da3793ee880f7f4724047d66d0536577e9ce7f2c58e20f18ab71001d37_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:f9f0d315879f335ad9b55cabb01ace7f71a2177c1723d9028752cc34c6db797a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:399c9418b53270433dcbe2f6b7c2954bf99e94a6ae1e191c6c068bff3cecb6b5_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:3f7b610c473e102539755b746171cc3230ee9eccadd1a92a5a94c10aac828cbc_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:5c3b2f6c3382ad5e309628ceae2336d8220ae2ca4adbb14db035f93240e32bcd_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:c938309c11e233db56e3abfa83d95a7fa81660e3c736274d20c4bc82e7825841_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c7daef8e89de0e096983b72e81eeae966cea075874f1ddc498e0f92b9d5a278d_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:dbaf78b7927d84af5cb0839937541970959ad7c22238e0ba1128eaf7605968b2_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f3ee104a6bda47b1fd75494d5cde518327d39a5b1e3db2353e3103a77d75baf0_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:181aedea4d725b0ccdce06a980be68ef9334043300c09ffb441801d44a12ab45_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:3b8ba974d1629d8b9be1b8b68484021fbf6c8f6ec66148392bf06f07c03fd0a5_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:5000afd21463cf3f153812c0370eda37b338f51d558548da09d816850dcc1bb6_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:9b294b80c238b3aad987a3bc6937140c06b9aaf8b36f3f0e6e789282c65bf67d_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:8f163428921db71291bf2aea1dfbd3fd45a29475574baad56084f0f92822a1a5_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:acda6ad07d02f508ae5556693e0e2e75e634057d405aaf8824fdbad7d1c42209_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:be297e14577cf786e37677f442896ad4439ecf0c917e29b20b359524a698f322_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:c67a725d086311a1424f75b3eb9af1899b40d062c4d1181d3a0e94284ea0e1db_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-eval-hub-rhel9@sha256:059445d96962b16c43a6374414ab18b9854c0dfa9739d25e4d84bfdf490e9750_s390x as a component of Red Hat OpenShift AI 3.4; and 23 more
After
exploit-intelligence-tech-preview/agent-client-rhel9 as a component of Exploit Intelligence; gatekeeper/gatekeeper-rhel9 as a component of Gatekeeper 3; mta/mta-ui-rhel8 as a component of Migration Toolkit for Applications 8; mta/mta-ui-rhel9 as a component of Migration Toolkit for Applications 8; rhmtc/openshift-migration-ui-rhel8 as a component of Migration Toolkit for Containers; migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; multicluster-engine/console-mce-rhel9 as a component of Multicluster Engine for Kubernetes; network-observability/network-observability-console-plugin-compat-rhel9 as a component of Network Observability Operator; network-observability/network-observability-console-plugin-rhel9 as a component of Network Observability Operator; workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-rhel9-operator as a component of Node HealthCheck Operator; openshift-lightspeed/lightspeed-console-plugin-419-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed; openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines; openshift-service-mesh/kiali-ossmc-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-operator-bundle as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-ossmc-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9-operator as a component of OpenShift Service Mesh 3; redhat-user-workloads/console-acm-211 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/console-acm-212 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/console-acm-213 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; and 125 more · Fixed: Red Hat Data Grid 8.6.2; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:34be19a6a0bc7ad5c47f85d4f0b676df88211d0687e5ff3853c8b9e901e6d542_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:397b15d36564af99170b2aaa57c7012d130b4d5bc45f1e2e80891329bf6f3944_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3a33448671868e7f6eb540a9adf1d0b544064f8494c6acdbaac2e6c9f49c4482_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5fdb1f33e2811ec60610b00f3c2dbadfd9673aa23969c5b2e6be495da9325cc2_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:b4a5fa8fb4a9f7f07f922b5d4aa92b9be30c9a2a905ca295e91be40b8a1f7b19_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c0bb08d3dea2add89b39261feac7775ca35b26cd294f8ae7f8dc02c4967676f9_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:d2dd5f64c3c111ff3f2b094d281a79a11e5f936c2b2995bc2026fc24671ed723_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f31bef6afba629e3c71da48e40c3e3f969589d38a6cefe28094cb962d7fc960e_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:0a3300adf425bc30ba99d2771948e08b571d239a852436438801756f741fbf5a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:0e9108dcd1e2144e21ed1fec40665cd0dc44b66a8c957fa3802db9478727b118_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:19395e8f07e6ed991317764bbd47ecada91719fea7cc79e2eb853426168c5fc7_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:24babc0af3dd8dd8588f91e72273ea148d3d58ab4de7ed4c45bf9e128a1028f8_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:5370a75973d1c0bdba5ab881260ffefbd03f1c604b4683d84b291a770543be35_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:6d2d42161d63652699784e04fa60b4dbf94d91f047abed68c8546e0e3b7c2a4c_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:e7889156e1ccdc1fdb55e7f25a3861e2edd3bc7b4d16ebc967d87aebce47b15f_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:f7b6fe3439bd36d31e7bcbe72180d63a4976943b54046fff86e393f49d2c71b6_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:0e8e3d0d3c979f9faffa203a2c50629744d9919505c090e3003603557c4c49dd_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:530108d282570507691074324644821930b9d4eb73a3ac7bebf0cae5490fede5_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:6781024e85e279457d34b5c6e42c72bcfb19768ef91e09a6afbb94e2ac7467c4_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:78d8d49a7da33dfe585e8ee12e3e029beb09748d624cbeda55a07ebfc273d996_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:9313f8478a794e84f4ee58eb5543d94ab8597a224dc41acd17ee513ea95d39eb_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:9fbd6ce682a8d4c78a2cb6874d038739a4960f6a24238fa8715b987342723167_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:cb7077da3793ee880f7f4724047d66d0536577e9ce7f2c58e20f18ab71001d37_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:f9f0d315879f335ad9b55cabb01ace7f71a2177c1723d9028752cc34c6db797a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:399c9418b53270433dcbe2f6b7c2954bf99e94a6ae1e191c6c068bff3cecb6b5_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:3f7b610c473e102539755b746171cc3230ee9eccadd1a92a5a94c10aac828cbc_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:4cc071d1b8f7d60bcd6a317bce0eb0534e3a52f6a8fbf230a34b5e8b9195a382_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:5c3b2f6c3382ad5e309628ceae2336d8220ae2ca4adbb14db035f93240e32bcd_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:70cfd7ce7ca6896f3ce38c045b80c4de4f21a77bb5a77d5118dcd8ba857121d4_s390x as a component of Red Hat OpenShift AI 3.3; and 39 more
Affected versionsThe structured affected or fixed version information changed.
Before
>= 7.7.0, < 7.13.2 · Fixed: No fixed version is explicitly recorded in the structured CVE data.
After
>= 7.7.0, < 7.13.2 · Fixed: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Affected versionsThe structured affected or fixed version information changed.
Before
exploit-intelligence-tech-preview/agent-client-rhel9 as a component of Exploit Intelligence; mta/mta-ui-rhel8 as a component of Migration Toolkit for Applications 8; mta/mta-ui-rhel9 as a component of Migration Toolkit for Applications 8; rhmtc/openshift-migration-ui-rhel8 as a component of Migration Toolkit for Containers; migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; network-observability/network-observability-console-plugin-compat-rhel9 as a component of Network Observability Operator; network-observability/network-observability-console-plugin-rhel9 as a component of Network Observability Operator; workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-rhel9-operator as a component of Node HealthCheck Operator; openshift-lightspeed/lightspeed-console-plugin-419-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed; openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines; openshift-service-mesh/kiali-ossmc-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-operator-bundle as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-ossmc-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9-operator as a component of OpenShift Service Mesh 3; advanced-cluster-security/rhacs-main-rhel8 as a component of Red Hat Advanced Cluster Security 4; react-router as a component of Red Hat AMQ Broker 7; react-router as a component of Red Hat build of Apache Camel - HawtIO 4; react-router as a component of Red Hat build of Apicurio Registry 2; apicurio/apicurio-registry-ui-rhel8 as a component of Red Hat build of Apicurio Registry 3; and 32 more · Fixed: Red Hat Data Grid 8.6.2; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3a33448671868e7f6eb540a9adf1d0b544064f8494c6acdbaac2e6c9f49c4482_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5fdb1f33e2811ec60610b00f3c2dbadfd9673aa23969c5b2e6be495da9325cc2_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:b4a5fa8fb4a9f7f07f922b5d4aa92b9be30c9a2a905ca295e91be40b8a1f7b19_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f31bef6afba629e3c71da48e40c3e3f969589d38a6cefe28094cb962d7fc960e_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:0a3300adf425bc30ba99d2771948e08b571d239a852436438801756f741fbf5a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:19395e8f07e6ed991317764bbd47ecada91719fea7cc79e2eb853426168c5fc7_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:24babc0af3dd8dd8588f91e72273ea148d3d58ab4de7ed4c45bf9e128a1028f8_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:f7b6fe3439bd36d31e7bcbe72180d63a4976943b54046fff86e393f49d2c71b6_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:0e8e3d0d3c979f9faffa203a2c50629744d9919505c090e3003603557c4c49dd_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:9313f8478a794e84f4ee58eb5543d94ab8597a224dc41acd17ee513ea95d39eb_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:cb7077da3793ee880f7f4724047d66d0536577e9ce7f2c58e20f18ab71001d37_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:f9f0d315879f335ad9b55cabb01ace7f71a2177c1723d9028752cc34c6db797a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:399c9418b53270433dcbe2f6b7c2954bf99e94a6ae1e191c6c068bff3cecb6b5_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:3f7b610c473e102539755b746171cc3230ee9eccadd1a92a5a94c10aac828cbc_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:5c3b2f6c3382ad5e309628ceae2336d8220ae2ca4adbb14db035f93240e32bcd_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:c938309c11e233db56e3abfa83d95a7fa81660e3c736274d20c4bc82e7825841_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c7daef8e89de0e096983b72e81eeae966cea075874f1ddc498e0f92b9d5a278d_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:dbaf78b7927d84af5cb0839937541970959ad7c22238e0ba1128eaf7605968b2_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f3ee104a6bda47b1fd75494d5cde518327d39a5b1e3db2353e3103a77d75baf0_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:181aedea4d725b0ccdce06a980be68ef9334043300c09ffb441801d44a12ab45_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:3b8ba974d1629d8b9be1b8b68484021fbf6c8f6ec66148392bf06f07c03fd0a5_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:5000afd21463cf3f153812c0370eda37b338f51d558548da09d816850dcc1bb6_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:9b294b80c238b3aad987a3bc6937140c06b9aaf8b36f3f0e6e789282c65bf67d_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:8f163428921db71291bf2aea1dfbd3fd45a29475574baad56084f0f92822a1a5_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:acda6ad07d02f508ae5556693e0e2e75e634057d405aaf8824fdbad7d1c42209_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:be297e14577cf786e37677f442896ad4439ecf0c917e29b20b359524a698f322_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:c67a725d086311a1424f75b3eb9af1899b40d062c4d1181d3a0e94284ea0e1db_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-eval-hub-rhel9@sha256:059445d96962b16c43a6374414ab18b9854c0dfa9739d25e4d84bfdf490e9750_s390x as a component of Red Hat OpenShift AI 3.4; and 23 more
After
exploit-intelligence-tech-preview/agent-client-rhel9 as a component of Exploit Intelligence; gatekeeper/gatekeeper-rhel9 as a component of Gatekeeper 3; mta/mta-ui-rhel8 as a component of Migration Toolkit for Applications 8; mta/mta-ui-rhel9 as a component of Migration Toolkit for Applications 8; rhmtc/openshift-migration-ui-rhel8 as a component of Migration Toolkit for Containers; migration-toolkit-virtualization/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; mtv-candidate/mtv-console-plugin-rhel9 as a component of Migration Toolkit for Virtualization; multicluster-engine/console-mce-rhel9 as a component of Multicluster Engine for Kubernetes; network-observability/network-observability-console-plugin-compat-rhel9 as a component of Network Observability Operator; network-observability/network-observability-console-plugin-rhel9 as a component of Network Observability Operator; workload-availability/node-healthcheck-must-gather-rhel9 as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-operator-bundle as a component of Node HealthCheck Operator; workload-availability/node-healthcheck-rhel9-operator as a component of Node HealthCheck Operator; openshift-lightspeed/lightspeed-console-plugin-419-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 as a component of OpenShift Lightspeed; openshift-lightspeed/lightspeed-console-plugin-rhel9 as a component of OpenShift Lightspeed; openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines; openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines; openshift-service-mesh/kiali-ossmc-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2; openshift-service-mesh/kiali-operator-bundle as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-ossmc-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3; openshift-service-mesh/kiali-rhel9-operator as a component of OpenShift Service Mesh 3; redhat-user-workloads/console-acm-211 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/console-acm-212 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; redhat-user-workloads/console-acm-213 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; and 125 more · Fixed: Red Hat Data Grid 8.6.2; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:3a33448671868e7f6eb540a9adf1d0b544064f8494c6acdbaac2e6c9f49c4482_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:5fdb1f33e2811ec60610b00f3c2dbadfd9673aa23969c5b2e6be495da9325cc2_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:b4a5fa8fb4a9f7f07f922b5d4aa92b9be30c9a2a905ca295e91be40b8a1f7b19_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f31bef6afba629e3c71da48e40c3e3f969589d38a6cefe28094cb962d7fc960e_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:0a3300adf425bc30ba99d2771948e08b571d239a852436438801756f741fbf5a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:19395e8f07e6ed991317764bbd47ecada91719fea7cc79e2eb853426168c5fc7_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:24babc0af3dd8dd8588f91e72273ea148d3d58ab4de7ed4c45bf9e128a1028f8_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-gen-ai-rhel9@sha256:f7b6fe3439bd36d31e7bcbe72180d63a4976943b54046fff86e393f49d2c71b6_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:0e8e3d0d3c979f9faffa203a2c50629744d9919505c090e3003603557c4c49dd_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:9313f8478a794e84f4ee58eb5543d94ab8597a224dc41acd17ee513ea95d39eb_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:cb7077da3793ee880f7f4724047d66d0536577e9ce7f2c58e20f18ab71001d37_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-maas-rhel9@sha256:f9f0d315879f335ad9b55cabb01ace7f71a2177c1723d9028752cc34c6db797a_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:399c9418b53270433dcbe2f6b7c2954bf99e94a6ae1e191c6c068bff3cecb6b5_ppc64le as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:3f7b610c473e102539755b746171cc3230ee9eccadd1a92a5a94c10aac828cbc_s390x as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:5c3b2f6c3382ad5e309628ceae2336d8220ae2ca4adbb14db035f93240e32bcd_arm64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-mod-arch-model-registry-rhel9@sha256:c938309c11e233db56e3abfa83d95a7fa81660e3c736274d20c4bc82e7825841_amd64 as a component of Red Hat OpenShift AI 3.3; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:c7daef8e89de0e096983b72e81eeae966cea075874f1ddc498e0f92b9d5a278d_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:dbaf78b7927d84af5cb0839937541970959ad7c22238e0ba1128eaf7605968b2_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:f3ee104a6bda47b1fd75494d5cde518327d39a5b1e3db2353e3103a77d75baf0_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:181aedea4d725b0ccdce06a980be68ef9334043300c09ffb441801d44a12ab45_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:3b8ba974d1629d8b9be1b8b68484021fbf6c8f6ec66148392bf06f07c03fd0a5_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:5000afd21463cf3f153812c0370eda37b338f51d558548da09d816850dcc1bb6_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:9b294b80c238b3aad987a3bc6937140c06b9aaf8b36f3f0e6e789282c65bf67d_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:8f163428921db71291bf2aea1dfbd3fd45a29475574baad56084f0f92822a1a5_amd64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:acda6ad07d02f508ae5556693e0e2e75e634057d405aaf8824fdbad7d1c42209_s390x as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:be297e14577cf786e37677f442896ad4439ecf0c917e29b20b359524a698f322_ppc64le as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-autorag-rhel9@sha256:c67a725d086311a1424f75b3eb9af1899b40d062c4d1181d3a0e94284ea0e1db_arm64 as a component of Red Hat OpenShift AI 3.4; registry.redhat.io/rhoai/odh-mod-arch-eval-hub-rhel9@sha256:059445d96962b16c43a6374414ab18b9854c0dfa9739d25e4d84bfdf490e9750_s390x as a component of Red Hat OpenShift AI 3.4; and 23 more
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.