VDB

RHEA-2021:3941

RHEA-2021:3941 PUBLISHED CVSS 6.5 MEDIUM

A flaw was found in golang. A panic can be triggered by an attacker in a privileged network position without access to the server certificate's private key, as long as a trusted ECDSA or Ed25519 certificate for the server exists (or can be issued), or the client is configured with Config.InsecureSkipVerify. Clients that disable all TLS_RSA cipher suites (that is, TLS 1.0–1.2 cipher suites without ECDHE), as well as TLS 1.3-only clients, are unaffected.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatopenshift-sandboxed-containers-tech-preview/osc-operator-bundle@sha256:a91cee14f47824ce49759628d06bf4e48276e67dae00b50123d3233d78531720_amd64 as a component of OpenShift Sandboxed Containers 1.1.0openshift-sandboxed-containers-tech-preview/osc-operator-bundle@sha256:a91cee14f47824ce49759628d06bf4e48276e67dae00b50123d3233d78531720_amd64
Red Hatopenshift-sandboxed-containers-tech-preview/osc-must-gather-rhel8@sha256:379aa6f59d25af015dba6a450851e7efb5b6ec6ac03e07f6325a00ab4cc43e3d_amd64 as a component of OpenShift Sandboxed Containers 1.1.0*
Red Hatopenshift-sandboxed-containers-tech-preview/osc-rhel8-operator@sha256:743499367a4891d0f6d4aae9bb1b370893c3b2ea492c59464192da305145f1b7_amd64 as a component of OpenShift Sandboxed Containers 1.1.0openshift-sandboxed-containers-tech-preview/osc-rhel8-operator@sha256:743499367a4891d0f6d4aae9bb1b370893c3b2ea492c59464192da305145f1b7_amd64

Timeline

  • Oct 20, 2021 CVE Published
  • Mar 27, 2026 CVE Updated
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›