Security features bypass in OpenShift Service Mesh and servicemesh-operator (Red Hat package) - CVE-2021-3586
Published: June 10, 2021
Vulnerability identifier: #VU54032
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3586
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists in the servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed allowing access to all ports on these resources from any pod.
Affected software
OpenShift Service Mesh
servicemesh-operator (Red Hat package)
servicemesh-operator (Red Hat package)
How to mitigate CVE-2021-3586
Install updates from vendor's website.
servicemesh-operator (Red Hat package) - update to 2.0.5-3.el8