CVE Vulnerabilities

CVE-2021-3703

Published: Aug 26, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.

Affected Software

NameVendorStart VersionEnd Version
Openshift_serverlessRedhat*1.17.0 (excluding)
Openshift Serverless 1.17RedHatopenshift-serverless-1/client-kn-rhel8:0.23.2-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-controller-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-mtbroker-filter-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-mtchannel-broker-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-mtping-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-storage-version-migration-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-sugar-controller-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/eventing-webhook-rhel8:0.23.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/ingress-rhel8-operator:1.17.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/knative-rhel8-operator:1.17.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/kn-cli-artifacts-rhel8:0.23.2-1*
Openshift Serverless 1.17RedHatopenshift-serverless-1/kourier-control-rhel8:0.23.0-4*
Openshift Serverless 1.17RedHatopenshift-serverless-1/net-istio-controller-rhel8:0.23.0-4*
Openshift Serverless 1.17RedHatopenshift-serverless-1/net-istio-webhook-rhel8:0.23.0-4*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serverless-operator-bundle:1.17.0-11*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serverless-rhel8-operator:1.17.0-5*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-activator-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-autoscaler-hpa-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-autoscaler-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-controller-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-domain-mapping-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-domain-mapping-webhook-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-queue-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-storage-version-migration-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/serving-webhook-rhel8:0.23.1-2*
Openshift Serverless 1.17RedHatopenshift-serverless-1/svls-must-gather-rhel8:1.17.0-5*
Openshift Serverless 1 on RHEL 8RedHatopenshift-serverless-clients-0:0.23.2-1.el8*

References