Security features bypass in OpenShift Service Mesh and servicemesh-operator (Red Hat package) - CVE-2021-3586

 

Security features bypass in OpenShift Service Mesh and servicemesh-operator (Red Hat package) - CVE-2021-3586

Published: June 10, 2021


Vulnerability identifier: #VU54032
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3586
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists in the servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed allowing access to all ports on these resources from any pod.


Affected software

OpenShift Service Mesh
servicemesh-operator (Red Hat package)

How to mitigate CVE-2021-3586

Install updates from vendor's website.

servicemesh-operator (Red Hat package) - update to 2.0.5-3.el8

External References

Related Security Bulletins