Lucene search

K
cveRedhatCVE-2021-3703
HistoryAug 26, 2022 - 4:15 p.m.

CVE-2021-3703

2022-08-2616:15:09
redhat
web.nvd.nist.gov
103
3
cve-2021-3703
nvd
rhsa
serverless
security update

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0.009

Percentile

82.3%

It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.

Affected configurations

Nvd
Vulners
Node
redhatopenshift_serverlessRange<1.17.0
VendorProductVersionCPE
redhatopenshift_serverless*cpe:2.3:a:redhat:openshift_serverless:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Serverless",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in Serverless 1.17.0"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.1

Confidence

High

EPSS

0.009

Percentile

82.3%