`TZInfo::Timezone.get` fails to validate time zone identifiers correctly, allowing a new line character within the identifier. `TZInfo::Timezone.get` can be made to load unintended files with `require`, executing them within the Ruby process. Reference: https://github.com/tzinfo/tzinfo/security/advisories/GHSA-5cm2-9h8c-rvfx
Created rubygem-tzinfo tracking bugs for this issue: Affects: epel-7 [bug 2110552]
This issue has been addressed in the following products: Red Hat Satellite 6.11 for RHEL 7 Red Hat Satellite 6.11 for RHEL 8 Via RHSA-2022:7242 https://access.redhat.com/errata/RHSA-2022:7242
This issue has been addressed in the following products: Red Hat Gluster Storage 3.5 for RHEL 7 Via RHSA-2023:1486 https://access.redhat.com/errata/RHSA-2023:1486
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-31163
This issue has been addressed in the following products: Red Hat Satellite 6.13 for RHEL 8 Via RHSA-2023:2097 https://access.redhat.com/errata/RHSA-2023:2097