Multiple vulnerabilities in OpenShift Container Platform 4.11

Published: 2023-04-05

Security Bulletin


This security bulletin contains information about 3 vulnerabilities.



1) Input validation error


EUVDB-ID: #VU74181


Risk: Medium


CVSSv3.1:


CVE-ID: CVE-2021-20329


CWE-ID: CWE-20 - Improper input validation


Exploit availability: No


Description

The vulnerability allows a remote attacker to manipulate data


The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can inject additional fields into marshalled documents and manipulate data in the database.


Mitigation

Install updates from vendor's website.


Vulnerable software versions

Red Hat OpenShift Container Platform: 4.11.0 - 4.11.33


CPE2.3
External links

http://access.redhat.com/errata/RHSA-2023:1504


Q & A


Can this vulnerability be exploited remotely?


Is there known malware, which exploits this vulnerability?




2) Input validation error


EUVDB-ID: #VU70478


Risk: Low


CVSSv3.1:


CVE-ID: CVE-2022-4318


CWE-ID: CWE-20 - Improper input validation


Exploit availability: No


Description

The vulnerability allows a local user to bypass certain security restrictions.


The vulnerability exists due to improper input validation when handling newline characters in environment variables. A local user can create a specially crafted environment variable and add entries to a container's /etc/passwd. It is also possible to circumvent admission validation of username/UID by adding such an entry.


..

Support the originator by clicking the read the rest link below.