The vendor explicitly identifies these products as affected by this CVE.
- rhacm2/volsync-operator-bundle as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- rhacm2/volsync-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop
- rhdh/red-hat-developer-hub-backstage-plugin-lightspeed as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgets as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator as a component of Red Hat Developer Hub
- rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
- mozjs60 as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in `adm-zip`, a Node.js library used for handling zip archives. This vulnerability allows a local attacker to overwrite arbitrary files on the system. When extracting an archive, `adm-zip` follows symbolic links, which are special files that point to other files or directories. An attacker can exploit this by placing a symbolic link within a temporary extraction directory, redirecting the extraction process to write data outside the intended secure location. This could lead to unauthorized modification of system files.
- Remediation
- Fix deferred
