Insufficient Entropy in GoUtils - CVE-2021-4238
Published: January 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient entropy when generating alphanumeric strings within RandomAlphaNumeric and CryptoRandomAlphaNumeric functions, which always return strings containing at least one digit from 0 to 9. A remote attacker can launch brute-force attacks and gain access to sensitive information.
Affected software
Red Hat OpenShift GitOps
Cloud Pak for Security (CP4S)
Cloud Pak for Data
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
servicemesh (Red Hat package)
servicemesh-operator (Red Hat package)
servicemesh-proxy (Red Hat package)
servicemesh-ratelimit (Red Hat package)
servicemesh-prometheus (Red Hat package)
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2021-4238
Cloud Pak for Security (CP4S) - update to 1.10.7.0
OpenShift Service Mesh - addressed in versions 2.1.6, 2.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.9.55, 4.10.51, 4.10.53, 4.10.54, 4.10.55, 4.11.26, 4.11.27, 4.11.28, 4.11.31, 4.11.32, 4.12.1, 4.12.2, 4.12.3, 4.12.4, 4.12.8, 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.12.1, 4.13.0
servicemesh (Red Hat package) - update to 2.1.6-1.el8
servicemesh-operator (Red Hat package) - update to 2.1.6-1.el8
servicemesh-proxy (Red Hat package) - update to 2.1.6-1.el8
servicemesh-ratelimit (Red Hat package) - update to 2.1.6-1.el8
servicemesh-prometheus (Red Hat package) - update to 2.23.0-10.el8
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Cloud Pak for Data - update to 4.8.5
External References
Related Security Bulletins
- Insufficient entropy in GoUtils
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.3
- Insufficient entropy in Red Hat OpenShift Service Mesh 2.1
- OpenShift Container Platform 4.12 update for GoUtils
- OpenShift Container Platform 4.11 update for GoUtils
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- OpenShift Container Platform 4.10 update for GoUtils
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- OpenShift Container Platform 4.12 update for goutils
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.12
- OpenShift Container Platform 4.11 update for GoUtils
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- OpenShift Container Platform 4.12 update for GoUtils
- OpenShift Container Platform 4.11 update for GoUtils
- OpenShift Container Platform 4.10 update for goutils
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Insufficient entropy in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Insufficient entropy in IBM Cloud Pak for Data