Show plain JSON{"affected_release": [{"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "acmesolver-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "acm-must-gather-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "acm-operator-bundle-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "application-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "cainjector-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "cert-manager-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "cert-manager-webhook-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "cert-policy-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "clusterlifecycle-state-metrics-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "configmap-watcher-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "config-policy-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "console-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "console-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "console-header-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "console-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "endpoint-component-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "endpoint-monitoring-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "endpoint-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "governance-policy-propagator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "governance-policy-spec-sync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "governance-policy-status-sync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "governance-policy-template-sync-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "grafana-dashboard-loader-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "grc-ui-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "grc-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "iam-policy-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "klusterlet-addon-lease-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "klusterlet-operator-bundle-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "kui-web-terminal-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "management-ingress-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "mcm-topology-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "mcm-topology-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "memcached-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "memcached-exporter-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "metrics-collector-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicloud-manager-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multiclusterhub-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multiclusterhub-repo-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-observability-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-operators-application-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-operators-channel-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-operators-deployable-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-operators-placementrule-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-operators-subscription-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "multicluster-operators-subscription-release-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "observatorium-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "observatorium-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "openshift-hive-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "rbac-query-proxy-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "rcm-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "redisgraph-tls-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "registration-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "registration-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "search-aggregator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "search-api-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "search-collector-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "search-operator-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "search-ui-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "submariner-addon-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "thanos-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "thanos-receive-controller-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}, {"advisory": "RHEA-2021:0729", "cpe": "cpe:/a:redhat:acm:2.2::el7", "package": "work-container", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2", "release_date": "2021-03-04T00:00:00Z"}], "bugzilla": {"description": "golang-github-buger-jsonparser: infinite loop via a Delete call", "id": "1817733", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1817733"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "status": "verified"}, "cwe": "CWE-835", "details": ["The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.", "A flaw was found in golang-github-buger-jsonparser. The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a delete call. The highest threat from this vulnerability is to system availability."], "name": "CVE-2020-10675", "package_state": [{"cpe": "cpe:/a:redhat:acm:2", "fix_state": "Not affected", "package_name": "jsonparser", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/cnf-tests-rhel8", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/file-integrity-rhel8-operator", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:openshift:4", "fix_state": "Not affected", "package_name": "openshift4/ose-container-networking-plugins-rhel8", "product_name": "Red Hat OpenShift Container Platform 4"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "cnv-containernetworking-plugins", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "hyperconverged-cluster-operator", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "kubemacpool", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "kubernetes-nmstate-handler", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "ovs-cni-marker", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "ovs-cni-plugin", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "virt-api", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "virt-controller", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "virt-handler", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "virt-launcher", "product_name": "Red Hat OpenShift Virtualization 2"}, {"cpe": "cpe:/a:redhat:container_native_virtualization:2", "fix_state": "Not affected", "package_name": "virt-operator", "product_name": "Red Hat OpenShift Virtualization 2"}], "public_date": "2020-03-09T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-10675\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-10675\nhttps://github.com/buger/jsonparser/issues/188"], "statement": "The OpenShift Container Platform 4 (OCP) containers, file-integrity-rhel8-operator, cnf-tests-rhel8 and ose-container-networking-plugins-rhel8, do have some references to github.com/buger/jsonparser, mainly in their go.sum files. However, it is not included in the final go build. It is also a dependency of the dependency github.com/containernetworking/plugins which only includes buger/jsonparse when compiling for Windows, which these containers do not. Hence, the associated containers have been marked not affected.\nOpenShift Virtualization cnv-containernetworking-plugins container depends on github.com/buger/jsonparser only when built for Windows, which it is not, thus it is not affected. Other OpenshiftVirtualization containers (virt-api, virt-controller, virt-handler, virt-launcher, virt-operator, kubernetes-nmstate-handler, ovs-cni-marker, ovs-cni-plugin, kubemacpool, hyperconverged-cluster-operator) have references to github.com/buger/jsonparser, however, it is not included in the final go build.", "threat_severity": "Moderate"}