Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 4 |
CVE-ID | CVE-2021-31525 CVE-2020-15586 CVE-2020-16845 CVE-2021-3114 |
CWE-ID | CWE-674 CWE-362 CWE-835 CWE-682 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
OpenShift Virtualization Server applications / Virtualization software |
Vendor | Red Hat Inc. |
This security bulletin contains information about 4 vulnerabilities.
EUVDB-ID: #VU54910
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-31525
CWE-ID:
CWE-674 - Uncontrolled Recursion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a DoS attack.
The vulnerability exists due to uncontrolled recursion when processing HTTP headers. A remote attacker can send a large header to ReadRequest or ReadResponse and perform a denial of service (DoS) attack.
Install updates from vendor's website.
OpenShift Virtualization: before 4.9.0
http://access.redhat.com/errata/RHSA-2021:4103
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU31891
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-15586
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler. A remote attacker can exploit the race and cause a denial of service condition on the target system.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: before 4.9.0
http://access.redhat.com/errata/RHSA-2021:4103
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU45699
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-16845
CWE-ID:
CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in "ReadUvarint" and "ReadVarint" in "encoding/binary". A remote attacker can consume all available system resources and cause denial of service conditions.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: before 4.9.0
http://access.redhat.com/errata/RHSA-2021:4103
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU50047
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-3114
CWE-ID:
CWE-682 - Incorrect Calculation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to incorrect calculation performed by the application in "crypto/elliptic/p224.go". A remote attacker can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: before 4.9.0
http://access.redhat.com/errata/RHSA-2021:4103
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?