The vendor explicitly identifies these products as affected by this CVE.
- rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-gaudi-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/disk-image-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in fastify. An authenticated low-privilege caller can exploit a vulnerability where the framework incorrectly processes the result of an Ajv asynchronous (async) validator. If a request body contains a root-level property named 'value', fastify replaces the entire request body with this property's content, bypassing the intended schema validation. This can lead to unauthorized state changes and the disclosure of sensitive data, as the application handler receives an unvalidated object.
- Remediation
- Affected
