{
  "threat_severity" : "Moderate",
  "public_date" : "2024-10-19T05:00:04Z",
  "bugzilla" : {
    "description" : "http-proxy-middleware: Denial of Service",
    "id" : "2319884",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2319884"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.", "A flaw was found in the http-proxy-middleware package. Affected versions of this package are vulnerable to denial of service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. This flaw allows an attacker to kill the Node.js process and crash the server by requesting certain paths." ],
  "affected_release" : [ {
    "product_name" : "Discovery 1 for RHEL 9",
    "release_date" : "2025-02-10T00:00:00Z",
    "advisory" : "RHSA-2025:1249",
    "cpe" : "cpe:/o:redhat:discovery:1.0::el9",
    "package" : "discovery/discovery-server-rhel9:1.12.0-1"
  }, {
    "product_name" : "Discovery 1 for RHEL 9",
    "release_date" : "2025-02-10T00:00:00Z",
    "advisory" : "RHSA-2025:1249",
    "cpe" : "cpe:/o:redhat:discovery:1.0::el9",
    "package" : "discovery/discovery-ui-rhel9:1.12.0-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-central-db-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-collector-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-collector-slim-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-operator-bundle:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-rhel8-operator:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-roxctl-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-db-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-slim-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.5",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3928",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.5::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-v4-rhel8:4.5.9-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-central-db-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-collector-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-collector-slim-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-operator-bundle:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-rhel8-operator:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-roxctl-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-db-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-slim-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.6",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.6::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-v4-rhel8:4.6.5-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-central-db-rhel8:4.7.2-2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-collector-rhel8:4.7.2-2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:4.7.2-3"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-operator-bundle:4.7.2-4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-rhel8-operator:4.7.2-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-roxctl-rhel8:4.7.2-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-db-rhel8:4.7.2-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.7.2-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-rhel8:4.7.2-2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-slim-rhel8:4.7.2-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-v4-db-rhel8:4.7.2-1"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-04-15T00:00:00Z",
    "advisory" : "RHSA-2025:3930",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-scanner-v4-rhel8:4.7.2-3"
  }, {
    "product_name" : "Red Hat Developer Hub 1.3 on RHEL 9",
    "release_date" : "2024-11-11T00:00:00Z",
    "advisory" : "RHBA-2024:9054",
    "cpe" : "cpe:/a:redhat:rhdh:1.3::el9",
    "package" : "rhdh/rhdh-hub-rhel9:1.3-124"
  }, {
    "product_name" : "Red Hat Migration Toolkit for Containers 1.8",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8510",
    "cpe" : "cpe:/a:redhat:rhmt:1.8::el8",
    "package" : "rhmtc/openshift-migration-ui-rhel8:v1.8.7-2"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/grafana-rhel8:2.6.3-2"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/istio-cni-rhel8:2.6.3-4"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/istio-must-gather-rhel8:2.6.3-3"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/istio-rhel8-operator:2.6.3-5"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/kiali-rhel8-operator:1.89.7-1"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/pilot-rhel8:2.6.3-4"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 8",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el8",
    "package" : "openshift-service-mesh/ratelimit-rhel8:2.6.3-4"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 2.6 for RHEL 9",
    "release_date" : "2024-11-14T00:00:00Z",
    "advisory" : "RHSA-2024:9627",
    "cpe" : "cpe:/a:redhat:service_mesh:2.6::el9",
    "package" : "openshift-service-mesh/proxyv2-rhel9:2.6.3-6"
  }, {
    "product_name" : "RHODF-4.14-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8551",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
    "package" : "odf4/ocs-client-console-rhel9:v4.14.18-2"
  }, {
    "product_name" : "RHODF-4.14-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8551",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
    "package" : "odf4/odf-console-rhel9:v4.14.18-3"
  }, {
    "product_name" : "RHODF-4.14-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8551",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.14::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:v4.14.18-2"
  }, {
    "product_name" : "RHODF-4.15-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8544",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.15::el9",
    "package" : "odf4/ocs-client-console-rhel9:v4.15.14-2"
  }, {
    "product_name" : "RHODF-4.15-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8544",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.15::el9",
    "package" : "odf4/odf-console-rhel9:v4.15.14-2"
  }, {
    "product_name" : "RHODF-4.15-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8544",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.15::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:v4.15.14-2"
  }, {
    "product_name" : "RHODF-4.16-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8479",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/ocs-client-console-rhel9:v4.16.10-4"
  }, {
    "product_name" : "RHODF-4.16-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8479",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-console-rhel9:v4.16.10-4"
  }, {
    "product_name" : "RHODF-4.16-RHEL-9",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8479",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.16::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:v4.16.10-3"
  }, {
    "product_name" : "RHODF-4.17-RHEL-9",
    "release_date" : "2025-05-21T00:00:00Z",
    "advisory" : "RHSA-2025:8059",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/ocs-client-console-rhel9:v4.17.7-2"
  }, {
    "product_name" : "RHODF-4.17-RHEL-9",
    "release_date" : "2025-05-21T00:00:00Z",
    "advisory" : "RHSA-2025:8059",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-console-rhel9:v4.17.7-2"
  }, {
    "product_name" : "RHODF-4.17-RHEL-9",
    "release_date" : "2025-05-21T00:00:00Z",
    "advisory" : "RHSA-2025:8059",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.17::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:v4.17.7-2"
  }, {
    "product_name" : "RHODF-4.18-RHEL-9",
    "release_date" : "2025-05-06T00:00:00Z",
    "advisory" : "RHSA-2025:4511",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/ocs-client-console-rhel9:v4.18.2-8"
  }, {
    "product_name" : "RHODF-4.18-RHEL-9",
    "release_date" : "2025-05-06T00:00:00Z",
    "advisory" : "RHSA-2025:4511",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-console-rhel9:v4.18.2-7"
  }, {
    "product_name" : "RHODF-4.18-RHEL-9",
    "release_date" : "2025-05-06T00:00:00Z",
    "advisory" : "RHSA-2025:4511",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.18::el9",
    "package" : "odf4/odf-multicluster-console-rhel9:v4.18.2-8"
  }, {
    "product_name" : "Red Hat Developer Hub (RHDH) 1.4",
    "release_date" : "2024-12-17T00:00:00Z",
    "advisory" : "RHBA-2024:11265",
    "cpe" : "cpe:/a:redhat:rhdh:1.4::el9",
    "package" : "rhdh/rhdh-hub-rhel9:sha256:48edcf6f736e17f33d3630ce2fddc19e95316b7824a7af24e9f0df48ac4f4fe3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.4",
    "release_date" : "2024-12-10T00:00:00Z",
    "advisory" : "RHSA-2024:10917",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.4::el8",
    "package" : "rhosdt/jaeger-query-rhel8:sha256:56784b527bf1fc1a2a0f24ea9b6edea3927746cbe1b18d9c653e0be621f07911"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.4",
    "release_date" : "2024-12-11T00:00:00Z",
    "advisory" : "RHSA-2024:10962",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.4::el8",
    "package" : "rhosdt/jaeger-query-rhel8:sha256:78b4c8cb7e68b33fbd0cfb502a2d4e3ca09eeb6168d525c80ae0a45775364952"
  }, {
    "product_name" : "Red Hat OpenShift Pipelines 1.16",
    "release_date" : "2025-06-04T00:00:00Z",
    "advisory" : "RHSA-2025:8512",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1.16::el8",
    "package" : "openshift-pipelines/pipelines-hub-ui-rhel8:sha256:3fc1b957039ba40b8d5353cd624b930f2bc5c5cb47335f7eb3255a8d792a3060"
  }, {
    "product_name" : "Red Hat OpenShift Pipelines 1.17",
    "release_date" : "2025-06-19T00:00:00Z",
    "advisory" : "RHSA-2025:9294",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1.17::el8",
    "package" : "openshift-pipelines/pipelines-hub-ui-rhel8:sha256:31ed62e58c9d12bff8cd88a881eda9b5e68d8d416227d191228dd0d3b4af532c"
  }, {
    "product_name" : "Red Hat OpenShift Pipelines 1.18.0",
    "release_date" : "2025-05-27T00:00:00Z",
    "advisory" : "RHSA-2025:8233",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1.18::el9",
    "package" : "openshift-pipelines/pipelines-hub-ui-rhel9:sha256:3c76479004dbe746cd677d6c8cbe957fd8272466bbeed4dc2cef9821fe7047ec"
  }, {
    "product_name" : "Red Hat OpenShift Pipelines 1.19",
    "release_date" : "2025-07-14T00:00:00Z",
    "advisory" : "RHSA-2025:10853",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1.19::el9",
    "package" : "openshift-pipelines/pipelines-console-plugin-rhel9:sha256:31eeeab213a1b603ab8c3f8253cd19c87bb45ca03e96e0461314571a7de82828"
  }, {
    "product_name" : "Red Hat OpenShift Pipelines 1.19",
    "release_date" : "2025-07-14T00:00:00Z",
    "advisory" : "RHSA-2025:10853",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1.19::el9",
    "package" : "openshift-pipelines/pipelines-hub-ui-rhel9:sha256:229db4f04e5de767027db6dcb560a527ff33d128c8aaa41d0580bb56197bdaa1"
  }, {
    "product_name" : "Red Hat Trusted Profile Analyzer 1.2",
    "release_date" : "2024-12-17T00:00:00Z",
    "advisory" : "RHSA-2024:11255",
    "cpe" : "cpe:/a:redhat:trusted_profile_analyzer:1.2::el9",
    "package" : "rhtpa/rhtpa-trustification-service-rhel9:sha256:8c6e51e26ca9a1d4d4fc9e90650103e60360cf0571533c56fbd08dac3007efbe"
  }, {
    "product_name" : "Red Hat Trusted Profile Analyzer 1.2",
    "release_date" : "2024-12-17T00:00:00Z",
    "advisory" : "RHSA-2024:11256",
    "cpe" : "cpe:/a:redhat:trusted_profile_analyzer:1.2::el9",
    "package" : "rhtpa/rhtpa-guac-rhel9:sha256:9cc0e1374aa5e6ff8caf86d9bbd6f9c2dfa14d812ad99ae653a2fbb8ec124f30"
  } ],
  "package_state" : [ {
    "product_name" : "Cryostat 3",
    "fix_state" : "Affected",
    "package_name" : "io.cryostat-cryostat3",
    "cpe" : "cpe:/a:redhat:cryostat:3"
  }, {
    "product_name" : "Logging Subsystem for Red Hat OpenShift",
    "fix_state" : "Not affected",
    "package_name" : "openshift-logging/kibana6-rhel8",
    "cpe" : "cpe:/a:redhat:logging:5"
  }, {
    "product_name" : "Logging Subsystem for Red Hat OpenShift",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-logging/logging-view-plugin-rhel8",
    "cpe" : "cpe:/a:redhat:logging:5"
  }, {
    "product_name" : "Migration Toolkit for Applications 7",
    "fix_state" : "Will not fix",
    "package_name" : "mta/mta-cli-rhel9",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:7"
  }, {
    "product_name" : "Migration Toolkit for Applications 7",
    "fix_state" : "Will not fix",
    "package_name" : "mta/mta-ui-rhel9",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:7"
  }, {
    "product_name" : "Migration Toolkit for Virtualization",
    "fix_state" : "Not affected",
    "package_name" : "migration-toolkit-virtualization/mtv-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:migration_toolkit_virtualization:2"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Not affected",
    "package_name" : "multicluster-engine/console-mce-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Not affected",
    "package_name" : "multicluster-engine/multicluster-engine-console-mce-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Node HealthCheck Operator",
    "fix_state" : "Will not fix",
    "package_name" : "workload-availability/node-remediation-console-rhel8",
    "cpe" : "cpe:/a:redhat:workload_availability_nhc:0"
  }, {
    "product_name" : "OpenShift Lightspeed",
    "fix_state" : "Affected",
    "package_name" : "openshift-lightspeed-beta/lightspeed-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_lightspeed"
  }, {
    "product_name" : "OpenShift Lightspeed",
    "fix_state" : "Affected",
    "package_name" : "openshift-lightspeed-tech-preview/lightspeed-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_lightspeed"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-pipelines/pipelines-hub-api-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-pipelines/pipelines-hub-db-migration-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Affected",
    "package_name" : "openshift-pipelines/pipelines-hub-ui-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Serverless",
    "fix_state" : "Not affected",
    "package_name" : "org.kie.kogito-kogito-apps",
    "cpe" : "cpe:/a:redhat:serverless:1"
  }, {
    "product_name" : "OpenShift Service Mesh 2",
    "fix_state" : "Affected",
    "package_name" : "openshift-service-mesh/kiali-rhel8",
    "cpe" : "cpe:/a:redhat:service_mesh:2"
  }, {
    "product_name" : "Red Hat 3scale API Management Platform 2",
    "fix_state" : "Will not fix",
    "package_name" : "3scale-amp-system-container",
    "cpe" : "cpe:/a:redhat:red_hat_3scale_amp:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Not affected",
    "package_name" : "rhacm2/console-rhel8",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Affected",
    "package_name" : "aap-cloud-ui-container",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Affected",
    "package_name" : "ansible-automation-platform-25/lightspeed-rhel8",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Affected",
    "package_name" : "automation-controller",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Not affected",
    "package_name" : "automation-eda-controller",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Affected",
    "package_name" : "automation-gateway",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2"
  }, {
    "product_name" : "Red Hat build of Apache Camel - HawtIO 4",
    "fix_state" : "Affected",
    "package_name" : "io.hawt-project",
    "cpe" : "cpe:/a:redhat:apache_camel_hawtio:4"
  }, {
    "product_name" : "Red Hat build of Apicurio Registry 2",
    "fix_state" : "Affected",
    "package_name" : "io.apicurio-apicurio-registry",
    "cpe" : "cpe:/a:redhat:service_registry:2"
  }, {
    "product_name" : "Red Hat build of OptaPlanner 8",
    "fix_state" : "Will not fix",
    "package_name" : "org.optaweb.vehiclerouting-optaweb-vehicle-routing",
    "cpe" : "cpe:/a:redhat:optaplanner:::el6"
  }, {
    "product_name" : "Red Hat Connectivity Link 1",
    "fix_state" : "Affected",
    "package_name" : "rhcl-console-plugin-container",
    "cpe" : "cpe:/a:redhat:connectivity_link:1"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Will not fix",
    "package_name" : "org.infinispan-infinispan-console",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Developer Hub",
    "fix_state" : "Not affected",
    "package_name" : "rhdh-operator-container",
    "cpe" : "cpe:/a:redhat:rhdh:1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "pcs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "pcs",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "io.apicurio-apicurito",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "io.syndesis-syndesis-parent",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "io.syndesis-syndesis-ui",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Will not fix",
    "package_name" : "io.apicurio-apicurio-registry",
    "cpe" : "cpe:/a:redhat:integration:1"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 7",
    "fix_state" : "Affected",
    "package_name" : "org.infinispan-infinispan-management-console",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Will not fix",
    "package_name" : "odh-dashboard-container",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Will not fix",
    "package_name" : "odh-operator-container",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/nmstate-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-console",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-monitoring-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-networking-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Data Science (RHODS)",
    "fix_state" : "Will not fix",
    "package_name" : "rhods/odh-dashboard-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_data_science"
  }, {
    "product_name" : "Red Hat OpenShift Data Science (RHODS)",
    "fix_state" : "Will not fix",
    "package_name" : "rhods/odh-operator-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_data_science"
  }, {
    "product_name" : "Red Hat OpenShift Data Science (RHODS)",
    "fix_state" : "Will not fix",
    "package_name" : "rhods/odh-rhel8-operator",
    "cpe" : "cpe:/a:redhat:openshift_data_science"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Not affected",
    "package_name" : "devspaces/traefik-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/jaeger-all-in-one-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/jaeger-collector-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/jaeger-es-index-cleaner-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Will not fix",
    "package_name" : "rhosdt/jaeger-es-rollover-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Will not fix",
    "package_name" : "rhosdt/jaeger-ingester-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3",
    "fix_state" : "Affected",
    "package_name" : "rhosdt/jaeger-query-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Affected",
    "package_name" : "openshift-gitops-1/argocd-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Affected",
    "package_name" : "openshift-gitops-1/argocd-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-gitops-1/argo-rollouts-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Affected",
    "package_name" : "openshift-gitops-1/console-plugin-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Will not fix",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Will not fix",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Not affected",
    "package_name" : "org.uberfire-uberfire-parent",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Not affected",
    "package_name" : "quay/quay-rhel8",
    "cpe" : "cpe:/a:redhat:quay:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-21536\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-21536\nhttps://gist.github.com/mhassan1/28be67266d82a53708ed59ce5dc3c94a\nhttps://github.com/chimurai/http-proxy-middleware/commit/0b4274e8cc9e9a2c5a06f35fbf456ccfcebc55a5\nhttps://github.com/chimurai/http-proxy-middleware/commit/788b21e4aff38332d6319557d4a5b1b13b1f9a22\nhttps://security.snyk.io/vuln/SNYK-JS-HTTPPROXYMIDDLEWARE-8229906" ],
  "name" : "CVE-2024-21536",
  "mitigation" : {
    "value" : "Red Hat Product Security does not have any mitigation recommendations at this time.",
    "lang" : "en:us"
  },
  "csaw" : false
}