CVE-2021-3636 - CVE House
Back to Database
Status published Medium CVE-2021-3636

It was found in OpenShift, before version 4.8, that the...

Vulnerability Description

It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclusion of additional CAs in this certificate would allow an attacker that compromises any of the additional CAs to masquerade as a trusted in-cluster service.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3636

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

openshift
Vulnerable Versions:
openshift 4.8

Timeline

Official Publish: July 30th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)