A out of bound write can occur when patching a Openshift object using the 'oc patch' functionality in OpenShift Container Platform 3.6 and earlier. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
A remote code execution vulnerability exists in Xterm.js before versions 3.8.1, 3.9.2 and 3.10.1 when the component mishandles special characters.
Upstream Releases:
https://github.com/xtermjs/xterm.js/releases/tag/3.8.1 https://github.com/xtermjs/xterm.js/releases/tag/3.9.2 https://github.com/xtermjs/xterm.js/releases/tag/3.10.1