Lucene search

K
cvelistRedhatCVELIST:CVE-2021-20198
HistoryFeb 23, 2021 - 5:45 p.m.

CVE-2021-20198

2021-02-2317:45:25
CWE-306
redhat
www.cve.org
5
openshift installer
remote code execution
kubelet port
unauthenticated
vulnerability
data confidentiality

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

52.1%

A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during installation can make unauthenticated /exec requests to execute arbitrary commands within running containers. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CNA Affected

[
  {
    "product": "openshift/installer",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "openshift/installer v0.9.0-master.0.20210125200451-95101da940b0"
      }
    ]
  }
]

AI Score

8.8

Confidence

High

EPSS

0.002

Percentile

52.1%

Related for CVELIST:CVE-2021-20198