VDB
RHSA-2023%3A3265
RHSA-2023%3A3265
PUBLISHED
CVSS 8.100000381469727 HIGH
A flaw was found in the jsonwebtoken package. The affected versions of the `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm.
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/mcg-rhel8-operator@sha256:2a393d0fe0de3da3358b578b123283f21b2433c6d50f1c512a48732409d11fce_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/mcg-rhel8-operator@sha256:2a393d0fe0de3da3358b578b123283f21b2433c6d50f1c512a48732409d11fce_ppc64le |
| Red Hat | odf4/odr-hub-operator-bundle@sha256:666c7cec9f2fd6d91b1839fd85576d84d0856a03b27e341e12f9c28ad301f594_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/odr-hub-operator-bundle@sha256:666c7cec9f2fd6d91b1839fd85576d84d0856a03b27e341e12f9c28ad301f594_amd64 |
| Red Hat | odf4/ocs-client-rhel8-operator@sha256:0f05a9eb9f6528447456ffab6f86a354990745c7d994095b4c9fa8a9748159ea_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-client-rhel8-operator@sha256:0f05a9eb9f6528447456ffab6f86a354990745c7d994095b4c9fa8a9748159ea_amd64 |
| Red Hat | odf4/ocs-client-operator-bundle@sha256:25252d3fabe165984b424b74437c428dc4f635aba06e245b3a1cc5e309bdf9df_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-client-operator-bundle@sha256:25252d3fabe165984b424b74437c428dc4f635aba06e245b3a1cc5e309bdf9df_ppc64le |
| Red Hat | odf4/odf-operator-bundle@sha256:f6182960abfce0ccb509a25ab8fb8780a8e2d73852d589e8295c16d992bb2ff6_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/odf-operator-bundle@sha256:f6182960abfce0ccb509a25ab8fb8780a8e2d73852d589e8295c16d992bb2ff6_amd64 |
| Red Hat | odf4/odf-csi-addons-rhel8-operator@sha256:f6a9c322c4dff132bbf01d1fc088a5988b5174ca953054c7d722bbd837b7d23b_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/odf-csi-addons-rhel8-operator@sha256:f6a9c322c4dff132bbf01d1fc088a5988b5174ca953054c7d722bbd837b7d23b_s390x |
| Red Hat | odf4/odf-csi-addons-operator-bundle@sha256:5c7ff483da2eb34694a59d2826d0e18309aff8f254650008ecfb5c03629d9442_amd64 as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/odf-multicluster-rhel8-operator@sha256:2d18752f56076d91b6fcbdad4e934cada87ba270532c522e7da2239f5b6f6d7d_ppc64le as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/odf-multicluster-operator-bundle@sha256:2afd8dc3f15a7eadad49f3c18d00ef9136dbf59f26e5b8345b16f92233dbd352_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/odf-multicluster-operator-bundle@sha256:2afd8dc3f15a7eadad49f3c18d00ef9136dbf59f26e5b8345b16f92233dbd352_s390x |
| Red Hat | odf4/odr-cluster-operator-bundle@sha256:7c89ebe7245e3514f6e63d1eca3247b0922e88d232b41c43245d2594e29b27d7_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/odr-cluster-operator-bundle@sha256:7c89ebe7245e3514f6e63d1eca3247b0922e88d232b41c43245d2594e29b27d7_ppc64le |
| Red Hat | odf4/cephcsi-rhel8@sha256:db90c6bf02b4e7b40538ed52ee4e3d27733c24bf434610277b26b2ee5ae32f53_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/cephcsi-rhel8@sha256:db90c6bf02b4e7b40538ed52ee4e3d27733c24bf434610277b26b2ee5ae32f53_amd64 |
| Red Hat | odf4/ocs-operator-bundle@sha256:5a7bc8abfd378a1314ebea571ba0483abaca80867fe7fdc1d0cb99772981a503_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-operator-bundle@sha256:5a7bc8abfd378a1314ebea571ba0483abaca80867fe7fdc1d0cb99772981a503_s390x |
| Red Hat | odf4/ocs-rhel8-operator@sha256:b9d941ef97de91ce2c67405c956f308ac39a966f88901cb7299c7d32f15fc1f6_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-rhel8-operator@sha256:b9d941ef97de91ce2c67405c956f308ac39a966f88901cb7299c7d32f15fc1f6_amd64 |
| Red Hat | odf4/odr-rhel8-operator@sha256:79b66652c0aea87822f578c55963ca948b2e1697caad5ea460e6555a78136039_amd64 as a component of RHODF 4.12 for RHEL 8 | odf4/odr-rhel8-operator@sha256:79b66652c0aea87822f578c55963ca948b2e1697caad5ea460e6555a78136039_amd64 |
| Red Hat | odf4/ocs-rhel8-operator@sha256:c5bb36336e3280dbc6fe2f969c73f40f31fbdfecf89e55b0bb8d2b83fa579644_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-rhel8-operator@sha256:c5bb36336e3280dbc6fe2f969c73f40f31fbdfecf89e55b0bb8d2b83fa579644_s390x |
| Red Hat | odf4/mcg-rhel8-operator@sha256:7c84f6197194047448c2d39d7d880555baf521d9c462e23b5342652eebcee3ec_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/mcg-rhel8-operator@sha256:7c84f6197194047448c2d39d7d880555baf521d9c462e23b5342652eebcee3ec_s390x |
| Red Hat | odf4/ocs-metrics-exporter-rhel8@sha256:7c4ab2dca6e1ebc5b89014e4ec253e19473d6ae44f0d150dd8e7d22458056300_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-metrics-exporter-rhel8@sha256:7c4ab2dca6e1ebc5b89014e4ec253e19473d6ae44f0d150dd8e7d22458056300_s390x |
| Red Hat | odf4/ocs-must-gather-rhel8@sha256:89a3457444d77fcc15546138ad259e2ccb29bfd7007dcb3dc3639c5a47c799c3_ppc64le as a component of RHODF 4.12 for RHEL 8 | odf4/ocs-must-gather-rhel8@sha256:89a3457444d77fcc15546138ad259e2ccb29bfd7007dcb3dc3639c5a47c799c3_ppc64le |
| Red Hat | odf4/odf-multicluster-console-rhel8@sha256:390481a9f0f0769056df89f5ce3cb2fbbeadf0e2f8d44469f68a9291e2d9fa48_s390x as a component of RHODF 4.12 for RHEL 8 | * |
| Red Hat | odf4/odf-operator-bundle@sha256:a912aa614bfd273fb6e6da47c32d00ca5aa4a45af3edfeb5f9f870ba4797a5ec_s390x as a component of RHODF 4.12 for RHEL 8 | odf4/odf-operator-bundle@sha256:a912aa614bfd273fb6e6da47c32d00ca5aa4a45af3edfeb5f9f870ba4797a5ec_s390x |
…and 49 more
Timeline
- May 23, 2023 CVE Published
- Mar 19, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:3265 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2150323 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2155978 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2167304 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2174336 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2177184 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2179235 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2180685 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2180724 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2183687 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2185190 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2185725 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2186443 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2186482 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2187765 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2187796 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2187799 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2188228 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2188327 issue
…and 16 more