CVE Vulnerabilities

CVE-2021-4235

Published: Dec 27, 2022 | Modified: Apr 11, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

Affected Software

NameVendorStart VersionEnd Version
YamlYaml_project*2.2.3 (excluding)
Red Hat OpenShift Container Platform 4.12RedHatopenshift-clients-0:4.12.0-202301042257.p0.g854f807.assembly.stream.el9*
Red Hat OpenShift Container Platform 4.12RedHatopenshift4/ose-installer:v4.12.0-202301271115.p0.g7fea1c4.assembly.stream*
Red Hat OpenShift Container Platform 4.12RedHatopenshift4/metallb-rhel8-operator:v4.12.0-202301301729.p0.g917cd33.assembly.stream*
Red Hat OpenShift Container Platform 4.12RedHatopenshift4/ose-openshift-controller-manager-rhel8:v4.12.0-202306090942.p0.gb6528f9.assembly.stream*
Red Hat OpenShift Container Platform 4.13RedHatopenshift4/ose-installer:v4.13.0-202305091542.p0.g44db7b2.assembly.stream*
Red Hat OpenShift Container Platform 4.13RedHatopenshift4/ose-machine-api-operator:v4.13.0-202304190216.p0.ga23baf7.assembly.stream*
RHODF-4.13-RHEL-9RedHatodf4/mcg-rhel9-operator:v4.13.0-41*
RHODF-4.13-RHEL-9RedHatodf4/odf-rhel9-operator:v4.13.0-24*
Golang-github-coreos-discovery-etcd-ioUbuntudevel*
Golang-github-coreos-discovery-etcd-ioUbuntuesm-apps/focal*
Golang-github-coreos-discovery-etcd-ioUbuntuesm-apps/jammy*
Golang-github-coreos-discovery-etcd-ioUbuntuesm-apps/noble*
Golang-github-coreos-discovery-etcd-ioUbuntufocal*
Golang-github-coreos-discovery-etcd-ioUbuntujammy*
Golang-github-coreos-discovery-etcd-ioUbuntukinetic*
Golang-github-coreos-discovery-etcd-ioUbuntulunar*
Golang-github-coreos-discovery-etcd-ioUbuntumantic*
Golang-github-coreos-discovery-etcd-ioUbuntunoble*
Golang-github-coreos-discovery-etcd-ioUbuntuoracular*
Golang-github-coreos-discovery-etcd-ioUbuntuplucky*
Golang-github-coreos-discovery-etcd-ioUbuntuquesting*
Golang-github-coreos-discovery-etcd-ioUbuntutrusty*
Golang-github-coreos-discovery-etcd-ioUbuntuxenial*
Golang-gopkg-yaml.v3Ubuntukinetic*
Golang-gopkg-yaml.v3Ubuntutrusty*
Golang-gopkg-yaml.v3Ubuntuxenial*
Golang-yaml.v2Ubuntubionic*
Golang-yaml.v2Ubuntuesm-apps/bionic*
Golang-yaml.v2Ubuntuesm-apps/focal*
Golang-yaml.v2Ubuntuesm-infra/xenial*
Golang-yaml.v2Ubuntufocal*
Golang-yaml.v2Ubuntukinetic*
Golang-yaml.v2Ubuntutrusty*
Golang-yaml.v2Ubuntuupstream*
Golang-yaml.v2Ubuntuxenial*
KubernetesUbuntufocal*
KubernetesUbuntukinetic*
KubernetesUbuntulunar*
KubernetesUbuntumantic*
KubernetesUbuntuoracular*
KubernetesUbuntutrusty*
KubernetesUbuntuxenial*
Singularity-containerUbuntubionic*
Singularity-containerUbuntuoracular*
Singularity-containerUbuntuplucky*
Singularity-containerUbuntutrusty*
Singularity-containerUbuntuxenial*
WebhookUbuntubionic*
WebhookUbuntufocal*
WebhookUbuntukinetic*
WebhookUbuntulunar*
WebhookUbuntumantic*
WebhookUbuntuoracular*
WebhookUbuntuplucky*
WebhookUbuntutrusty*
WebhookUbuntuxenial*

References