CVE Vulnerabilities

CVE-2021-3703

Published: Aug 26, 2022 | Modified: Sep 01, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu

It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.

Affected Software

Name Vendor Start Version End Version
Openshift_serverless Redhat * 1.17.0 (excluding)
Openshift Serverless 1.17 RedHat openshift-serverless-1/client-kn-rhel8:0.23.2-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-controller-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-mtbroker-filter-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-mtchannel-broker-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-mtping-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-storage-version-migration-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-sugar-controller-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/eventing-webhook-rhel8:0.23.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/ingress-rhel8-operator:1.17.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/knative-rhel8-operator:1.17.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/kn-cli-artifacts-rhel8:0.23.2-1 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/kourier-control-rhel8:0.23.0-4 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/net-istio-controller-rhel8:0.23.0-4 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/net-istio-webhook-rhel8:0.23.0-4 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serverless-operator-bundle:1.17.0-11 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serverless-rhel8-operator:1.17.0-5 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-activator-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-autoscaler-hpa-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-autoscaler-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-controller-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-domain-mapping-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-domain-mapping-webhook-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-queue-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-storage-version-migration-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/serving-webhook-rhel8:0.23.1-2 *
Openshift Serverless 1.17 RedHat openshift-serverless-1/svls-must-gather-rhel8:1.17.0-5 *
Openshift Serverless 1 on RHEL 8 RedHat openshift-serverless-clients-0:0.23.2-1.el8 *

References