Show plain JSON{"affected_release": [{"advisory": "RHBA-2022:1352", "cpe": "cpe:/a:redhat:rhel_dotnet:3.1::el7", "package": "rh-dotnet31-dotnet-0:3.1.418-1.el7_9", "product_name": ".NET Core on Red Hat Enterprise Linux", "release_date": "2022-04-13T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "acm-grafana-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "acm-must-gather-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "acm-operator-bundle-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "application-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "assisted-image-service-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "cert-policy-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "cluster-backup-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "clusterclaims-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "cluster-curator-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "clusterlifecycle-state-metrics-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "cluster-proxy-addon-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "config-policy-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "console-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "console-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "discovery-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "endpoint-monitoring-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "governance-policy-propagator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "governance-policy-spec-sync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "governance-policy-status-sync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "governance-policy-template-sync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "grafana-dashboard-loader-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "grc-ui-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "grc-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "iam-policy-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "insights-client-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "insights-metrics-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "klusterlet-addon-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "klusterlet-addon-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "kube-rbac-proxy-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "kube-state-metrics-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "managedcluster-import-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "management-ingress-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "memcached-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "memcached-exporter-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "metrics-collector-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicloud-integrations-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicloud-manager-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multiclusterhub-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multiclusterhub-repo-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-observability-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-operators-application-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-operators-channel-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-operators-deployable-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-operators-placementrule-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-operators-subscription-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "multicluster-operators-subscription-release-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "node-exporter-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "observatorium-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "observatorium-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "openshift-hive-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "placement-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "prometheus-alertmanager-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "prometheus-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "provider-credential-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "rbac-query-proxy-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "redisgraph-tls-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "registration-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "registration-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "rhacm-agent-service-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "rhacm-assisted-installer-agent-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "rhacm-assisted-installer-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "rhacm-assisted-installer-reporter-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "search-aggregator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "search-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "search-collector-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "search-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "search-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "submariner-addon-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "thanos-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "thanos-receive-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "volsync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "volsync-mover-rclone-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "volsync-mover-restic-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "volsync-mover-rsync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1681", "cpe": "cpe:/a:redhat:acm:2.4::el8", "package": "work-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2022-05-03T00:00:00Z"}, {"advisory": "RHSA-2022:1715", "cpe": "cpe:/a:redhat:acm:2.3::el8", "package": "rhacm2/application-ui-rhel8:v2.3.10-6", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8", "release_date": "2022-05-05T00:00:00Z"}, {"advisory": "RHBA-2022:1386", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "dotnet3.1-0:3.1.418-1.el8_5", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2022-04-18T00:00:00Z"}, {"advisory": "RHSA-2022:8652", "cpe": "cpe:/a:redhat:jboss_fuse:7", "package": "urijs", "product_name": "Red Hat Fuse 7.11.1", "release_date": "2022-11-28T00:00:00Z"}], "bugzilla": {"description": "urijs: Authorization Bypass Through User-Controlled Key", "id": "2055496", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2055496"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "status": "verified"}, "cwe": "CWE-178->CWE-639", "details": ["Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.", "A flaw was found in urijs due to the fix of CVE-2021-3647 not considering case-sensitive protocol schemes in the URL. This issue allows attackers to bypass the patch."], "name": "CVE-2022-0613", "package_state": [{"cpe": "cpe:/a:redhat:rhel_dotnet:5.0", "fix_state": "Out of support scope", "package_name": "rh-dotnet50-dotnet", "product_name": ".NET Core 5.0 on Red Hat Enterprise Linux"}, {"cpe": "cpe:/a:redhat:acm:2", "fix_state": "Will not fix", "package_name": "rhacm2/mcm-topology-rhel8", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Will not fix", "package_name": "dotnet5.0", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/a:redhat:quay:3", "fix_state": "Affected", "package_name": "quay/quay-rhel8", "product_name": "Red Hat Quay 3"}], "public_date": "2022-02-16T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2022-0613\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-0613"], "threat_severity": "Moderate"}