CVE Vulnerabilities

CVE-2021-4235

Published: Dec 27, 2022 | Modified: Jul 06, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.

Affected Software

Name Vendor Start Version End Version
Yaml Yaml_project * 2.2.3 (excluding)
Red Hat OpenShift Container Platform 4.12 RedHat openshift-clients-0:4.12.0-202301042257.p0.g854f807.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-installer:v4.12.0-202301271115.p0.g7fea1c4.assembly.stream *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/metallb-rhel8-operator:v4.12.0-202301301729.p0.g917cd33.assembly.stream *
Red Hat OpenShift Container Platform 4.12 RedHat openshift4/ose-openshift-controller-manager-rhel8:v4.12.0-202306090942.p0.gb6528f9.assembly.stream *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-installer:v4.13.0-202305091542.p0.g44db7b2.assembly.stream *
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/ose-machine-api-operator:v4.13.0-202304190216.p0.ga23baf7.assembly.stream *
RHODF-4.13-RHEL-9 RedHat odf4/mcg-rhel9-operator:v4.13.0-41 *
RHODF-4.13-RHEL-9 RedHat odf4/odf-rhel9-operator:v4.13.0-24 *
Golang-github-coreos-discovery-etcd-io Ubuntu kinetic *
Golang-github-coreos-discovery-etcd-io Ubuntu lunar *
Golang-github-coreos-discovery-etcd-io Ubuntu mantic *
Golang-github-coreos-discovery-etcd-io Ubuntu trusty *
Golang-github-coreos-discovery-etcd-io Ubuntu xenial *
Golang-gopkg-yaml.v3 Ubuntu kinetic *
Golang-gopkg-yaml.v3 Ubuntu trusty *
Golang-gopkg-yaml.v3 Ubuntu xenial *
Golang-yaml.v2 Ubuntu bionic *
Golang-yaml.v2 Ubuntu esm-apps/bionic *
Golang-yaml.v2 Ubuntu esm-infra/xenial *
Golang-yaml.v2 Ubuntu focal *
Golang-yaml.v2 Ubuntu kinetic *
Golang-yaml.v2 Ubuntu trusty *
Golang-yaml.v2 Ubuntu upstream *
Golang-yaml.v2 Ubuntu xenial *
Kubernetes Ubuntu kinetic *
Kubernetes Ubuntu lunar *
Kubernetes Ubuntu mantic *
Kubernetes Ubuntu trusty *
Kubernetes Ubuntu xenial *
Singularity-container Ubuntu bionic *
Singularity-container Ubuntu trusty *
Singularity-container Ubuntu xenial *
Webhook Ubuntu bionic *
Webhook Ubuntu kinetic *
Webhook Ubuntu lunar *
Webhook Ubuntu mantic *
Webhook Ubuntu trusty *
Webhook Ubuntu xenial *

References