VDB

CVE-2020-27836

CVE-2020-27836 PUBLISHED CVSS 9.800000190734863 CRITICAL

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..

EPSS 1.19% · 65.7th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.19%
65.7th percentile

Affected Products

VendorProductVersions
redhatopenshift_container_platform4.6
n/acluster-ingress-operator*

Timeline

  • Aug 22, 2022 CVE Published
  • Aug 23, 2022 EPSS Score
  • Oct 8, 2022 EPSS Score
  • Nov 23, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Feb 23, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 10, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Aug 25, 2023 EPSS Score
  • Oct 10, 2023 EPSS Score
  • Nov 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›