Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09395

Опубликовано: 23 мар. 2026
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость библиотеки Picomatch связана с неконтролируемым изменением атрибутов прототипа объекта. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, оказать воздействие на целостность данных

Вендор

Red Hat Inc.
ООО «РусБИТех-Астра»
Сообщество свободного программного обеспечения
АО «СберТех»

Наименование ПО

Red Hat Enterprise Linux
Red Hat Single Sign-On
Red Hat Quay
Red Hat AMQ Broker
Data Grid
Red Hat Process Automation
Red Hat 3scale API Management Platform
Red Hat Openshift Data Foundation
Red Hat OpenShift GitOps
Red Hat OpenShift Container Platform
Red Hat Satellite
Node HealthCheck Operator
Red Hat JBoss Enterprise Application Platform
Red Hat build of OptaPlanner
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security
Red Hat Build of Keycloak
Red Hat Fuse
Red Hat Trusted Artifact Signer
Red Hat build of Apicurio Registry
Red Hat build of Apache Camel
Cryostat
Streams for Apache Kafka
Ansible Automation Platform
Migration Toolkit for Applications
Red Hat Build of Podman Desktop
ПК СВ «Брест»
Picomatch
Platform V IAM SE

Версия ПО

8 (Red Hat Enterprise Linux)
7 (Red Hat Single Sign-On)
3 (Red Hat Quay)
7 (Red Hat AMQ Broker)
8 (Data Grid)
7 (Red Hat Process Automation)
2 (Red Hat 3scale API Management Platform)
4 (Red Hat Openshift Data Foundation)
- (Red Hat OpenShift GitOps)
4 (Red Hat OpenShift Container Platform)
6 (Red Hat Satellite)
9 (Red Hat Enterprise Linux)
- (Node HealthCheck Operator)
7 (Red Hat JBoss Enterprise Application Platform)
8 (Red Hat build of OptaPlanner)
- (Red Hat OpenShift Dev Spaces)
4 (Red Hat Advanced Cluster Security)
- (Red Hat Build of Keycloak)
8 (Red Hat JBoss Enterprise Application Platform)
7 (Red Hat Fuse)
- (Red Hat Trusted Artifact Signer)
2 (Red Hat build of Apicurio Registry)
10 (Red Hat Enterprise Linux)
HawtIO 4 (Red Hat build of Apache Camel)
4 (Cryostat)
2 (Streams for Apache Kafka)
3 (Streams for Apache Kafka)
2 (Ansible Automation Platform)
8 (Migration Toolkit for Applications)
- (Red Hat Build of Podman Desktop)
до 4.0.2 (ПК СВ «Брест»)
до 2.3.2 (Picomatch)
от 3.0.0 до 3.0.2 (Picomatch)
от 4.0.0 до 4.0.4 (Picomatch)
до 2.3.1 (Platform V IAM SE)

Тип ПО

Операционная система
Сетевое программное средство
Прикладное ПО информационных систем
Средство защиты

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 10

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)

Возможные меры по устранению уязвимости

В условиях отсутствия обновлений безопасности от производителя рекомендуется придерживаться "Рекомендаций по безопасной настройке операционных систем LINUX", изложенных в методическом документе ФСТЭК России, утверждённом 25 декабря 2022 года.
Использование рекомендаций:
Для Picomatch:
https://github.com/micromatch/picomatch/security/advisories/GHSA-3v7f-55p6-f55p
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-33672
Для ПК СВ «Брест»:
обновление программного обеспечения, применение оперативного обновления ПК СВ «Брест» 4.0.2, предоставляемого в личном кабинете пользователя https://lk.astralinux.ru/ (https://wiki.astralinux.ru/x/ziLoD)
Для Platform V IAM SE:
Обновление до версии Platform V IAM SE 2.3.1

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 33%
0.0041
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames. The issue does not enable remote code execution, but it can cause security-relevant logic errors in applications that rely on glob matching for filtering, validation, or access control. All users of affected `picomatch` versions that process untrusted or user-controlled glob patterns are potentially impacted. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending ...

CVSS3: 5.3
redhat
4 месяца назад

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames. The issue does not enable remote code execution, but it can cause security-relevant logic errors in applications that rely on glob matching for filtering, validation, or access control. All users of affected `picomatch` versions that process untrusted or user-controlled glob patterns are potentially impacted. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending ...

CVSS3: 5.3
nvd
4 месяца назад

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames. The issue does not enable remote code execution, but it can cause security-relevant logic errors in applications that rely on glob matching for filtering, validation, or access control. All users of affected `picomatch` versions that process untrusted or user-controlled glob patterns are potentially impacted. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on

CVSS3: 5.3
msrc
4 месяца назад

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

CVSS3: 5.3
debian
4 месяца назад

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0. ...

EPSS

Процентиль: 33%
0.0041
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2