6.8
CVSSv2

CVE-2021-20198

Published: 23/02/2021 Updated: 27/02/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during installation can make unauthenticated `/exec` requests to execute arbitrary commands within running containers. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift installer

Vendor Advisories

Synopsis Important: OpenShift Container Platform 4531 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4531 is now available withupdates to packages and images that fix several bugsThis release also includes a security update for ...
Synopsis Important: OpenShift Container Platform 4616 security and bug fix update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4616 is now available withupdates to packages and images that fix several bugsRed Hat Product Security has rated this update as ...