CVE-2021-4125
published 2022-08-24CVE-2021-4125: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all…
PriorityP342high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.19%
64.7th percentile
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kube-reporting | hive | — | — |
| redhat | openshift | >= 4.6.0 < 4.6.52 | 4.6.52 |
| redhat | openshift | >= 4.7.0 < 4.7.40 | 4.7.40 |
| redhat | openshift | >= 4.8.0 < 4.8.24 | 4.8.24 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
vendor_redhat·2021-12-16·CVSS 8.1
CVE-2021-4125 [HIGH] kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.
Statement: This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6. The below previously shipped advisories were incomplete:
https://access.redhat.com/errata/RHSA-2021:5108
https://acc
GHSA
GHSA-jr7q-cc2x-97vj: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all Jn
ghsa_unreviewed·2022-08-25·CVSS 10.0
CVE-2021-4125 [CRITICAL] CWE-502 GHSA-jr7q-cc2x-97vj: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all Jn
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-4125https://access.redhat.com/security/cve/CVE-2021-44228https://access.redhat.com/security/cve/CVE-2021-45046https://bugzilla.redhat.com/show_bug.cgi?id=2033121https://github.com/kube-reporting/hive/pull/71https://github.com/kube-reporting/hive/pull/72https://github.com/kube-reporting/hive/pull/73https://access.redhat.com/security/cve/CVE-2021-4125https://access.redhat.com/security/cve/CVE-2021-44228https://access.redhat.com/security/cve/CVE-2021-45046https://bugzilla.redhat.com/show_bug.cgi?id=2033121https://github.com/kube-reporting/hive/pull/71https://github.com/kube-reporting/hive/pull/72https://github.com/kube-reporting/hive/pull/73
2022-08-24
Published