Lucene search

K
cveRedhatCVE-2020-27836
HistoryAug 22, 2022 - 3:15 p.m.

CVE-2020-27836

2022-08-2215:15:12
CWE-732
redhat
web.nvd.nist.gov
47
4
cve-2020-27836
cluster-ingress-operator
vulnerability
unauthorized access
data confidentiality
data integrity
system availability
nvd.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

58.7%

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability…

Affected configurations

Nvd
Vulners
Node
redhatenterprise_linuxMatch8.0
AND
redhatopenshift_container_platformMatch4.6
VendorProductVersionCPE
redhatenterprise_linux8.0cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
redhatopenshift_container_platform4.6cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "cluster-ingress-operator",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in ose-cluster-ingress-operator-container-v4.6.0-202012161211.p0."
      }
    ]
  }
]

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

58.7%

Related for CVE-2020-27836