CVE-2021-20278

Related Vulnerabilities: CVE-2021-20278  

No description is available for this CVE.

Description

No description is available for this CVE.

Statement

OpenShift ServiceMesh (OSSM) kiali is configured to delegate authorization to the OpenShift's RBAC user rights and the OpenID authentication strategy is not supported, hence it is marked `not affected`.

OpenShift ServiceMesh (OSSM) kiali is configured to delegate authorization to the OpenShift's RBAC user rights and the OpenID authentication strategy is not supported, hence it is marked not affected.

Additional Information

  • Bugzilla 1937171: CVE-2021-20278 kiali: authentication bypass when using the OpenID login strategy
  • CWE-290: Authentication Bypass by Spoofing
  • FAQ: Frequently asked questions about CVE-2021-20278