cbcvebase.
CVE-2021-3636
published 2021-07-30

CVE-2021-3636: It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The…

PriorityP419medium4.6CVSS 3.1
AVAACLPRLUINSUCLILAN
EPSS
0.28%
20.6th percentile
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclusion of additional CAs in this certificate would allow an attacker that compromises any of the additional CAs to masquerade as a trusted in-cluster service.

Affected

5 ranges
VendorProductVersion rangeFixed in
msrccbl2_cri-o_1.21.7-3_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatopenshift< 4.84.8
redhatopenshift

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.04.1MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:N
vendor_msrc4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.