VDB
CVE-2020-27836
CVE-2020-27836
PUBLISHED
CVSS 9.800000190734863 CRITICAL
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
EPSS 1.19% · 65.7th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.19%
65.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | openshift_container_platform | 4.6 |
| n/a | cluster-ingress-operator | * |
Timeline
- Aug 22, 2022 CVE Published
- Aug 23, 2022 EPSS Score
- Oct 8, 2022 EPSS Score
- Nov 23, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 10, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 25, 2023 EPSS Score
- Oct 10, 2023 EPSS Score
- Nov 25, 2023 EPSS Score