VDB
CVE-2021-3948
CVE-2021-3948
PUBLISHED
CVSS 6.300000190734863 MEDIUM
An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.
EPSS 0.13% · 32.2th percentile
Risk Scores
CVSS v3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.13%
32.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | mig-controller | * |
| konveyor | mig-controller | 0, 1.6.0 |
| redhat | migration_toolkit | 1.0, 1.5, 1.6 |
Timeline
- Feb 18, 2022 CVE Published
- Feb 19, 2022 EPSS Score
- Apr 12, 2022 EPSS Score
- Jun 3, 2022 EPSS Score
- Jul 26, 2022 EPSS Score
- Sep 16, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Dec 29, 2022 EPSS Score
- Feb 19, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 12, 2023 EPSS Score
- Jun 3, 2023 EPSS Score