VDB
RHSA-2021%3A0949
RHSA-2021%3A0949
PUBLISHED
CVSS 7.5 HIGH
It was discovered that the "setElementTypePrefix()" function incorrectly extracted XML namespace prefixes. By tricking an application into processing a specially crafted XML file, an attacker could cause unusually high consumption of memory resources and possibly lead to a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshiftdo/odo-init-image-rhel7@sha256:83eea230500106cf84b287fb7249be475171c8ff9ced7025cbf628a213cb9d96_amd64 as a component of OpenShift Do 1 | *, * |
Timeline
- Mar 22, 2021 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:0949 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://docs.openshift.com/container-platform/4.4/cli_reference/openshift_developer_cli/installing-odo.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1832983 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0949.json advisory
- https://access.redhat.com/security/cve/CVE-2018-20843 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1723723 issue
- https://www.cve.org/CVERecord?id=CVE-2018-20843 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20843 advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931031 advisory
- https://access.redhat.com/security/cve/CVE-2019-5094 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1768555 issue
- https://www.cve.org/CVERecord?id=CVE-2019-5094 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-5094 advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0887 advisory
- https://access.redhat.com/security/cve/CVE-2019-5188 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1790048 issue
- https://www.cve.org/CVERecord?id=CVE-2019-5188 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-5188 advisory
- https://access.redhat.com/security/cve/CVE-2019-5482 advisory
…and 132 more