CVE-2021-4047Improper Input Validation in Redhat Openshift

Severity
7.5HIGHNVD
EPSS
0.2%
top 57.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateApr 12

Description

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5redhat/openshiftOpenShift 4.9

🔴Vulnerability Details

2
GHSA
GHSA-v3g6-gh83-x752: The release of OpenShift 42022-04-12
CVEList
CVE-2021-4047: The release of OpenShift 42022-04-11

📋Vendor Advisories

1
Red Hat
haproxy: Incomplete fix for CVE-2021-39242 in OpenShift 4.92021-11-30
CVE-2021-4047 — Improper Input Validation in Redhat | cvebase