This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype. Ps.: The fixed version is not fixed completely in 0.11.4 as it stills affects org.webjars.npm:nconf. References: https://snyk.io/vuln/SNYK-JS-NCONF-2395478 https://github.com/indexzero/nconf/releases/tag/v0.11.4 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2632450 https://github.com/indexzero/nconf/pull/397
services-insights-essentials/remediations/insights-remediations:f169564/nconf-0.10.0 https://github.com/RedHatInsights/insights-remediations/blob/master/package-lock.json services-insights-essentials/remediations/remediations:f169564/nconf-0.10.0 https://github.com/RedHatInsights/insights-remediations/blob/production/package-lock.json
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8 Via RHSA-2022:1681 https://access.redhat.com/errata/RHSA-2022:1681
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Via RHSA-2022:1715 https://access.redhat.com/errata/RHSA-2022:1715
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-21803
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.5 for RHEL 8 Via RHSA-2022:4956 https://access.redhat.com/errata/RHSA-2022:4956
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8 Via RHSA-2022:5201 https://access.redhat.com/errata/RHSA-2022:5201
This issue has been addressed in the following products: Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 7 Via RHSA-2022:5392 https://access.redhat.com/errata/RHSA-2022:5392