VDB
RHSA-2022%3A9040
RHSA-2022%3A9040
PUBLISHED
CVSS 7.5 HIGH
A vulnerability was found in the nodejs-minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhacm2/cluster-backup-rhel8-operator@sha256:486b767a84eabfc0b0cff6c960e0c45cffb964435d87edc594e92b736bc188a7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | * |
| Red Hat | rhacm2/kube-state-metrics-rhel8@sha256:73044ccae125bd75b599567d0ebf08f133757fcba55c3d033144782a42492118_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/kube-state-metrics-rhel8@sha256:73044ccae125bd75b599567d0ebf08f133757fcba55c3d033144782a42492118_arm64 |
| Red Hat | rhacm2/governance-policy-template-sync-rhel8@sha256:c1860c9dbe1ba622761ab2fd1612053b28ac979724e6f76e7022de99f936602e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/governance-policy-template-sync-rhel8@sha256:c1860c9dbe1ba622761ab2fd1612053b28ac979724e6f76e7022de99f936602e_arm64 |
| Red Hat | rhacm2/governance-policy-template-sync-rhel8@sha256:e605a7da078a386a33cdb0873c02a7e81ed7d34d723e3a739f93c693dd56c3a7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/governance-policy-template-sync-rhel8@sha256:e605a7da078a386a33cdb0873c02a7e81ed7d34d723e3a739f93c693dd56c3a7_ppc64le |
| Red Hat | rhacm2/acm-prometheus-config-reloader-rhel8@sha256:d39f60038997f995a159e1f9f7d58838f4bea27feec43061399ac0b49a4283dc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/acm-prometheus-config-reloader-rhel8@sha256:d39f60038997f995a159e1f9f7d58838f4bea27feec43061399ac0b49a4283dc_arm64 |
| Red Hat | rhacm2/multicluster-operators-subscription-rhel8@sha256:1b0805e059570d78204cd90362abd5be51bae68ee6d68a16b7253a796e84ab95_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | * |
| Red Hat | rhacm2/memcached-exporter-rhel8@sha256:621499f5e4008d5da2f747c71df84fc22c61d384472a175ff4974c607b58bab0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/memcached-exporter-rhel8@sha256:621499f5e4008d5da2f747c71df84fc22c61d384472a175ff4974c607b58bab0_amd64 |
| Red Hat | rhacm2/governance-policy-propagator-rhel8@sha256:7695a160568b7ec52f8325da984abd4e6703289040020c8c63d146833d34109d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/governance-policy-propagator-rhel8@sha256:7695a160568b7ec52f8325da984abd4e6703289040020c8c63d146833d34109d_s390x |
| Red Hat | rhacm2/multiclusterhub-repo-rhel8@sha256:66e88b74afb4b1d7ee4d83e47cff514234ce36ff61e5a50110963edcadcac52a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/multiclusterhub-repo-rhel8@sha256:66e88b74afb4b1d7ee4d83e47cff514234ce36ff61e5a50110963edcadcac52a_ppc64le |
| Red Hat | rhacm2/multiclusterhub-rhel8@sha256:2d40857f0ab5b654c9fed86007e943269e691e424bdd34a37a4391e469b85b6f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/multiclusterhub-rhel8@sha256:2d40857f0ab5b654c9fed86007e943269e691e424bdd34a37a4391e469b85b6f_amd64 |
| Red Hat | rhacm2/governance-policy-propagator-rhel8@sha256:4b98fddbadd599896e3b764b46c8540a4d479508c2bae373acce62a9a3136838_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/governance-policy-propagator-rhel8@sha256:4b98fddbadd599896e3b764b46c8540a4d479508c2bae373acce62a9a3136838_amd64 |
| Red Hat | rhacm2/acm-must-gather-rhel8@sha256:6b5550b372570898f0d5b3dcae9252faf5b96252b6e943abffb8d99e110f4ea6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/acm-must-gather-rhel8@sha256:6b5550b372570898f0d5b3dcae9252faf5b96252b6e943abffb8d99e110f4ea6_arm64 |
| Red Hat | rhacm2/thanos-rhel8@sha256:76e0bcee8c17bdafa057def3bf3cdb0086b5c6098fac58b2474d431cf848750f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | * |
| Red Hat | rhacm2/thanos-receive-controller-rhel8@sha256:73ebc2239443c185e46239ebc1100b8c945701b26f8eca31a13b4718c2b2a512_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/thanos-receive-controller-rhel8@sha256:73ebc2239443c185e46239ebc1100b8c945701b26f8eca31a13b4718c2b2a512_amd64 |
| Red Hat | rhacm2/search-aggregator-rhel8@sha256:d0046873c8908a14953fd5dba03db185cc03203a6f8dfc04a7a89e3175b996d1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/search-aggregator-rhel8@sha256:d0046873c8908a14953fd5dba03db185cc03203a6f8dfc04a7a89e3175b996d1_s390x |
| Red Hat | rhacm2/klusterlet-addon-controller-rhel8@sha256:384b8e10a099f9233e210e4e34e1ae900cc9fd7dd7fbdfd5977819266a56554f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | * |
| Red Hat | rhacm2/console-rhel8@sha256:08873157eef623ceb3482d49e7d13db26954c995afda3ed7c9bb54f327c87558_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/console-rhel8@sha256:08873157eef623ceb3482d49e7d13db26954c995afda3ed7c9bb54f327c87558_ppc64le |
| Red Hat | rhacm2/search-aggregator-rhel8@sha256:d0b22f1a90f86f059ecb5e3f9804e5f4f258860c05c4e5bab529e8335e5fee43_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/search-aggregator-rhel8@sha256:d0b22f1a90f86f059ecb5e3f9804e5f4f258860c05c4e5bab529e8335e5fee43_amd64 |
| Red Hat | rhacm2/multicluster-operators-channel-rhel8@sha256:5a269382be7cc13f315ca5f3b3d1f14ee1c7ddce06d00be7844346cc33bda9c5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/multicluster-operators-channel-rhel8@sha256:5a269382be7cc13f315ca5f3b3d1f14ee1c7ddce06d00be7844346cc33bda9c5_s390x |
| Red Hat | rhacm2/cluster-backup-rhel8-operator@sha256:78db56efe92cdbcb02b90a01f5810f340870f8ea65ce13d64968c8f35388dc40_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.6 for RHEL 8 | rhacm2/cluster-backup-rhel8-operator@sha256:78db56efe92cdbcb02b90a01f5810f340870f8ea65ce13d64968c8f35388dc40_ppc64le |
…and 171 more
Timeline
- Dec 14, 2022 CVE Published
- Apr 29, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:9040 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2129679 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2134609 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2139085 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2149181 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_9040.json advisory
- https://access.redhat.com/security/cve/CVE-2022-3517 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3517 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3517 advisory
- https://access.redhat.com/security/cve/CVE-2022-41912 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41912 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41912 advisory
- https://github.com/crewjam/saml/security/advisories/GHSA-j2jp-wvqg-wc2g advisory