IBM Support

Security Bulletin: Red Hat OpenShift on IBM Cloud is affected by a Kubernetes API server security vulnerability (CVE-2021-25737)

Security Bulletin


Summary

Red Hat OpenShift on IBM Cloud is affected by a security vulnerability in the Kubernetes API server that could allow a user to redirect pod traffic to private networks on a node (CVE-2021-25737).

Vulnerability Details

CVEID: CVE-2021-25737
Description: Kubernetes could allow a remote authenticated attacker to obtain sensitive information, caused by a host network hijacking flaw due to holes in EndpointSlice validation. By redirecting pod traffic to private networks on a Node, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVSS Base Score: 2.7
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/202128 for more information
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Red Hat OpenShift on IBM Cloud 4.3-4.7
Red Hat OpenShift on IBM Cloud 3.11

Remediation/Fixes

Red Hat OpenShift on IBM Cloud version 4.8 is available to fix this vulnerability. Customers must upgrade their clusters to version 4.8 to address the vulnerability.

Customers running Red Hat OpenShift on IBM Cloud clusters at version 4.5, 4.6 or 4.7 must upgrade their clusters to version 4.8. Please review the documentation before starting an upgrade since additional actions may be required.

Customers running Red Hat OpenShift on IBM Cloud clusters at version 3.11, 4.3 or 4.4 must create a new cluster at version 4.8 and deploy their apps to the new cluster.

Red Hat OpenShift on IBM Cloud versions 4.3, 4.4 and 4.5 are no longer supported and version 3.11 is deprecated. See the Red Hat OpenShift on IBM Cloud version information and update actions documentation for more information about OpenShift versions and version support policies.

Monitor IBM Cloud Status for Future Security Bulletins

Monitor the security notifications on the IBM Cloud Status page to be advised of future security bulletins.

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSJTBP","label":"IBM Cloud Kubernetes Service and Red Hat OpenShift on IBM Cloud"},"Component":"--","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB21","label":"Public Cloud Platform"}}]

Document Information

Modified date:
18 November 2021

UID

ibm16517054