Authorization bypass through user-controlled key in NPM url-parse prior to 1.5.6. Reference: https://huntr.dev/bounties/6d1bc51f-1876-4f5b-a2c2-734e09e8e05b Upstream patch: https://github.com/unshiftio/url-parse/commit/9be7ee88afd2bb04e4d5a1a8da9a389ac13f8c40
marking services affected/fix services-ccx/advisor-frontend:a764354/url-parse-1.5.1 https://github.com/RedHatInsights/ocp-advisor-frontend/blob/prod-stable/package-lock.json services-management-platform/frontend-starter-app/frontend-starter-app:2b2ef7d/url-parse-1.5.1 https://github.com/RedHatInsights/sed-frontend/blob/master/package-lock.json quay-io-3/quayio/quay:09e783d/url-parse-1.4.0 https://github.com/quay/quay/blob/quayio/package-lock.json quay-io-3/quayio/quay:09e783d/url-parse-1.4.0 https://github.com/quay/quay/blob/quayio/yarn.lock services-rhods/rhods/jupyterhub-odh:64e363a/url-parse-1.4.7 https://github.com/red-hat-data-services/jupyterhub-odh/blob/master/package-lock.json services-assisted-installer/facet:b119ef2/url-parse-1.5.3 https://github.com/openshift-assisted/assisted-ui/blob/master/yarn.lock services-assisted-installer/ui:33db575/url-parse-1.5.3 https://github.com/openshift-assisted/assisted-ui-lib/blob/master/yarn.lock services-drift/drift/drift-frontend:d87d582/url-parse-1.5.3 https://github.com/RedHatInsights/drift-frontend/blob/master/package-lock.json services-rhcert/rhcert-spa:ae8c43b/url-parse-1.5.3 https://gitlab.cee.redhat.com/certification/rhcert-spa/blob/master/package-lock.json services-rhcert/rhcert-spa:ae8c43b/url-parse-1.5.3 https://gitlab.cee.redhat.com/certification/rhcert-spa/blob/master/yarn.lock
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.7 Via RHSA-2022:6429 https://access.redhat.com/errata/RHSA-2022:6429
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-0512