Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
1) Input validation error
EUVDB-ID: #VU74181
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-20329
CWE-ID: CWE-20 - Improper input validation
Exploit availability: No
Description
The vulnerability allows a remote attacker to manipulate data
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can inject additional fields into marshalled documents and manipulate data in the database.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Red Hat OpenShift Container Platform: 4.11.0 - 4.11.33
CPE2.3
External links
http://access.redhat.com/errata/RHSA-2023:1504
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
2) Input validation error
EUVDB-ID: #VU70478
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-4318
CWE-ID: CWE-20 - Improper input validation
Exploit availability: No
Description
The vulnerability allows a local user to bypass certain security restrictions.
The vulnerability exists due to improper input validation when handling newline characters in environment variables. A local user can create a specially crafted environment variable and add entries to a container's /etc/passwd. It is also possible to circumvent admission validation of username/UID by adding such an entry.
..
Support the originator by clicking the read the rest link below.