Improper input validation in Oracle Communications Cloud Native Core Unified Data Repository - CVE-2020-8554
Published: January 27, 2022
Vulnerability details
The vulnerability allows a remote authenticated user to read and manipulate data.
The vulnerability exists due to improper input validation within the UDR (Kubernetes API) component in Oracle Communications Cloud Native Core Unified Data Repository. A remote authenticated user can exploit this vulnerability to read and manipulate data.
Affected software
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
python-urllib3 (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
Red Hat OpenShift Container Platform
IBM Observability with Instana
How to mitigate CVE-2020-8554
Red Hat OpenShift Container Platform - update to 3.11.374
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.374-1.git.0.3abd2a5.el7
openshift-ansible (Red Hat package) - update to 3.11.374-1.git.0.92f5956.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.374-1.git.0.2996f62.el7
atomic-openshift (Red Hat package) - update to 3.11.374-1.git.0.ebd3ee9.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.374-1.git.15.523a1f7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.374-1.git.53.9df25a9.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.374-1.git.218.9cf7939.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.374-1.git.263.28335fb.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.374-1.git.299.f128e96.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.374-1.git.379.80bd08f.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.374-1.git.439.966c536.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.374-1.git.481.e6a880c.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.374-1.git.647.9e78d83.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.374-1.git.1062.490d6d5.el7
openshift-kuryr (Red Hat package) - update to 3.11.374-1.git.1478.ef11824.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.374-1.git.1675.738abcc.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.374-1.git.5026.29379c4.el7
IBM Observability with Instana - update to 279
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 3.11