An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B’s state.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Forge | Digitalbazaar | * | 1.3.1 (including) |
| Migration Toolkit for Virtualization 2.9 | RedHat | migration-toolkit-virtualization/mtv-console-plugin-rhel9:sha256:5d385ba67a8d8158790da4511586c190a24a194e2ccb10fcb7182b658a59c624 | * |
| Red Hat Advanced Cluster Security 4.8 | RedHat | advanced-cluster-security/rhacs-main-rhel8:sha256:438b4904d97ca6cd51284955f284c0b078af30859460eb1ed608e20535ccc2c8 | * |
| Red Hat Developer Hub 1.7 | RedHat | rhdh/rhdh-hub-rhel9:sha256:29ada5e84c6b204cf518191a21bbd22de5cb53a61bc1812b1072ce5c28a235b2 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:sha256:8af6fd7c8fe38d6bfd22e42810badde0aeeae738ea28667ae29dbc0cf4266f3e | * |
| Red Hat OpenShift Service Mesh 2.6 | RedHat | openshift-service-mesh/kiali-ossmc-rhel8:sha256:c34b5d86b07705fd0d610ba37bb54a5612b6aba81f04e661b207a2eb0209bea2 | * |
| Red Hat OpenShift Service Mesh 2.6 | RedHat | openshift-service-mesh/kiali-rhel8:sha256:5fa584e152eb852c9f9dd2ec07c4857924a87470bb92934cbd48efdb0ca238ba | * |
| Red Hat OpenShift Service Mesh 3.0 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:284ba4bea2d340c325d183b866efb72527d297ab6c866b7b18c9e82af43d6af3 | * |
| Red Hat OpenShift Service Mesh 3.0 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:c012e5fdf21c90d8d504164ddec9b294c5c347df078049fcd4e20a9ebe2f76cc | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:502dcba52460677c5d20f2649216e62c426acb83fbfb38bd630e942b9c0c2733 | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:9d884a817a1a1e8924b6405e694ffae05f78664f4e00f355ec2ddd7c05446e53 | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:sha256:7d670f57a84d17b7be55c897a286654b44f75abeafd81669f89467320018b4ef | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-rhel9:sha256:04c798a54632613681f4ff9d07b88b79722dba1cdba1a6e8166ec94a252a81e6 | * |
| Red Hat Quay 3.16 | RedHat | quay/quay-rhel9:sha256:ff78174701ecd4c840dff59667f0790419f850771f6726973434bf5fd6e81687 | * |