The vendor explicitly identifies these products as affected by this CVE.
- openshift-sandboxed-containers/osc-pccs as a component of Confidential Compute Attestation
- io.cryostat-cryostat as a component of Cryostat 4
- rhmtc/openshift-migration-ui-rhel8 as a component of Migration Toolkit for Containers
- network-observability/network-observability-console-plugin-compat-rhel9 as a component of Network Observability Operator
- openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-api-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-db-migration-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-hub-ui-rhel9 as a component of OpenShift Pipelines
- openshift-service-mesh/kiali-rhel8 as a component of OpenShift Service Mesh 2
- openshift-service-mesh/kiali-operator-bundle as a component of OpenShift Service Mesh 3
- openshift-service-mesh/kiali-rhel9 as a component of OpenShift Service Mesh 3
- Summary
- A flaw was found in `@tootallnate/once`. When the `AbortSignal` option is used, a Promise can remain in a permanently pending state after the signal is aborted. This incorrect control flow scoping can lead to stalled requests, blocked workers, or degraded application availability.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
