Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20198

Опубликовано: 23 фев. 2021
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during installation can make unauthenticated /exec requests to execute arbitrary commands within running containers. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:openshift_installer:*:*:*:*:*:*:*:*
Версия до 0.9.0-master.0.20210125200451-95101da940b0 (исключая)

EPSS

Процентиль: 68%
0.00558
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.1
redhat
почти 5 лет назад

A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during installation can make unauthenticated `/exec` requests to execute arbitrary commands within running containers. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS

Процентиль: 68%
0.00558
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-306