Back to bug 2129802

Who When What Removed Added
Avinash Hanwate 2022-09-26 10:13:57 UTC CC alazarot, chazlett, cluster-maint, dwhatley, dymurray, emingora, etirelli, gparvin, ibek, ibolton, idevat, jmatthew, jmontleo, jramanat, jrokos, jshaughn, jstastny, jwendell, jwon, kmalyjur, krathod, kverlaen, mlisik, mnovotny, mpospisi, nboldt, njean, omular, oskutka, ovanders, pahickey, pjindal, rcernich, rguimara, rrajasek, scorneli, slucidi, sseago, stcannon, tkral, tojeline, tzimanyi
Avinash Hanwate 2022-09-26 10:14:45 UTC Blocks 2129803
Avinash Hanwate 2022-10-06 02:51:53 UTC Depends On 2132516, 2132517, 2132515, 2132514
Avinash Hanwate 2022-10-06 02:53:03 UTC Depends On 2132518, 2132519
Tomáš Král 2022-10-21 07:26:39 UTC CC tkral
Red Hat Bugzilla 2022-10-28 13:13:09 UTC CC krathod
Red Hat Bugzilla 2022-11-14 23:22:52 UTC CC jstastny
Avinash Hanwate 2023-01-09 05:58:57 UTC Depends On 2159188
Red Hat Bugzilla 2023-02-03 23:11:35 UTC CC ovanders
Avinash Hanwate 2023-03-16 04:17:57 UTC Doc Text A flaw was found in the hapi/hoek package. hapi.js hoek could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw in the clone() function. By adding or modifying properties of Object.prototype using a __proto__ or constructor payload, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
Paige Jung 2023-03-16 15:00:10 UTC Doc Text A flaw was found in the hapi/hoek package. hapi.js hoek could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw in the clone() function. By adding or modifying properties of Object.prototype using a __proto__ or constructor payload, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system. A prototype pollution flaw was found the clone() function of the hapi/hoek package. By adding or modifying properties of Object.prototype using a __proto__ or constructor payload, an attacker could execute arbitrary code or cause a denial of service condition on the system.
Red Hat Bugzilla 2023-05-15 18:03:57 UTC CC rrajasek
Red Hat Bugzilla 2023-07-07 08:34:50 UTC Assignee security-response-team nobody

Back to bug 2129802