The vendor explicitly identifies these products as affected by this CVE.
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator as a component of Red Hat Developer Hub
- rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
- ansible-automation-platform/automation-portal as a component of Self-service automation portal 2
- ansible-automation-platform/bootc-automation-portal-rhel9 as a component of Self-service automation portal 2
- Summary
- A flaw was found in isomorphic-git. This prototype pollution vulnerability in the getRemoteInfo function allows a malicious Git server operator to manipulate object properties by advertising specially crafted reference names. This can reroute network operations through an attacker-controlled proxy, leading to the transmission of user credentials to the attacker.
- Remediation
- Affected
