Risk | High |
Patch available | YES |
Number of vulnerabilities | 12 |
CVE-ID | CVE-2022-1996 CVE-2021-45485 CVE-2021-45486 CVE-2022-2588 CVE-2022-3515 CVE-2022-21123 CVE-2022-21125 CVE-2022-21166 CVE-2022-38177 CVE-2022-38178 CVE-2022-40674 CVE-2022-41974 |
CWE-ID | CWE-942 CWE-200 CWE-415 CWE-190 CWE-401 CWE-416 CWE-285 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #4 is available. |
Vulnerable software Subscribe |
OpenShift Virtualization Server applications / Virtualization software |
Vendor | Red Hat Inc. |
This security bulletin contains information about 12 vulnerabilities.
EUVDB-ID: #VU66447
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-1996
CWE-ID:
CWE-942 - Overly Permissive Cross-domain Whitelist
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass the CORS protection mechanism.
The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request. A remote attacker can supply arbitrary value via the "Origin" HTTP header, bypass implemented CORS protection mechanism and perform cross-site scripting attacks against the vulnerable application.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU63668
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-45485
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error in the IPv6 implementation in the Linux kernel. A remote attacker can gain access to sensitive information.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU63577
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-45486
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to incorrect implementation of the IPv4 protocol in the Linux kernel. A remote attacker can disclose internal state in some situations.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU66397
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-2588
CWE-ID:
CWE-415 - Double Free
Exploit availability: Yes
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The
vulnerability exists due to a double free error within the network packet scheduler implementation
in the route4_change() function in Linux kernel when removing all references to a route filter
before freeing it. A local user can run a specially crafted program to
crash the kernel or execute arbitrary code.
Install updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68376
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-3515
CWE-ID:
CWE-190 - Integer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the CRL parser in libksba. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU64364
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-21123
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows an attacker to gain access to potentially sensitive information.
The vulnerability exists in Intel processors due to excessive data output when DirectPath I/O (PCI-Passthrough) is utilized. An attacker (both local and remote) with administrative access to a virtual machine that has an attached DirectPath I/O (PCI-Passthrough) device can obtain information stored in physical memory about the hypervisor or other virtual machines that reside on the same host.
Install updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU64365
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-21125
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows an attacker to gain access to potentially sensitive information.
The vulnerability exists in Intel processors due to excessive data output when DirectPath I/O (PCI-Passthrough) is utilized. An attacker (both local and remote) with administrative access to a virtual machine that has an attached DirectPath I/O (PCI-Passthrough) device can obtain information stored in physical memory about the hypervisor or other virtual machines that reside on the same host.
Install updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU64366
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-21166
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows an attacker to gain access to potentially sensitive information.
The vulnerability exists in Intel processors due to excessive data output when DirectPath I/O (PCI-Passthrough) is utilized. An attacker (both local and remote) with administrative access to a virtual machine that has an attached DirectPath I/O (PCI-Passthrough) device can obtain information stored in physical memory about the hypervisor or other virtual machines that reside on the same host.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU67549
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-38177
CWE-ID:
CWE-401 - Improper Release of Memory Before Removing Last Reference ('Memory Leak')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in the DNSSEC verification code for the ECDSA algorithm. A remote attacker can spoof the target resolver with responses that have a malformed ECDSA signature and perform denial of service attack.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU67550
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2022-38178
CWE-ID:
CWE-401 - Improper Release of Memory Before Removing Last Reference ('Memory Leak')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in the DNSSEC verification code for the EdDSA algorithm. A remote attacker can spoof the target resolver with responses that have a malformed EdDSA signature and perform denial of service attack.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU67532
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-40674
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the doContent() function in xmlparse.c. A remote attacker can pass specially crafted input to the application that is using the affected library, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationInstall updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU68722
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-41974
CWE-ID:
CWE-285 - Improper Authorization
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrectly implemented authorization process within multipathd daemon. A local unprivileged user can bypass build-in authorization and execute privileged commands on the system.
Install updates from vendor's website.
OpenShift Virtualization: 4.9.0 - 4.9.6
http://access.redhat.com/errata/RHSA-2022:8609
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?