Bug 2050897 - CVE-2022-0235 mcg-core-container: node-fetch: exposure of sensitive information to an unauthorized actor [openshift-data-foundation-4]
Summary: CVE-2022-0235 mcg-core-container: node-fetch: exposure of sensitive informati...
Keywords:
Status: CLOSED ERRATA
Alias: None
Deadline: 2022-07-15
Product: Red Hat OpenShift Data Foundation
Classification: Red Hat Storage
Component: Multi-Cloud Object Gateway
Version: 4.9
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: ODF 4.11.0
Assignee: Liran Mauda
QA Contact: Elad
URL:
Whiteboard:
Depends On:
Blocks: CVE-2022-0235
TreeView+ depends on / blocked
 
Reported: 2022-02-04 21:37 UTC by Sage McTaggart
Modified: 2023-08-09 16:49 UTC (History)
9 users (show)

Fixed In Version: 4.11.0-89
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-08-24 13:48:26 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github noobaa noobaa-core pull 6951 0 None Merged Bump core dependencies 2022-06-07 08:57:17 UTC
Red Hat Product Errata RHSA-2022:6156 0 None None None 2022-08-24 13:49:38 UTC

Description Sage McTaggart 2022-02-04 21:37:51 UTC
openshift-container-storage-4 tracking bug for noobaa-operator-container: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).

This bug is never intended to be made public, please put any public notes in the blocked bugs.

Impact: Low.
Public Date: 16-Jan-2022
PM Fix/Wontfix Decision By: Per SLA
Resolve Bug By: Per SLA

In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this bug.

Please see the Security Errata Policy for further details: https://docs.engineering.redhat.com/x/9RBqB

Comment 12 errata-xmlrpc 2022-08-24 13:48:26 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Important: Red Hat OpenShift Data Foundation 4.11.0 security, enhancement, & bugfix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2022:6156


Note You need to log in before you can comment on or make changes to this bug.