VDB
RHSA-2021%3A2130
RHSA-2021%3A2130
PUBLISHED
CVSS 5.800000190734863 MEDIUM
A flaw was found in the Windows kube-proxy component. In a cloud environment that does not set the “.status.loadBalancer.ingress.ip” field in the LoadBalancer service status configuration (for example in AWS) the packets can be misrouted and reach an unintended destination.
Risk Scores
CVSS 3.1
5.800000190734863
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:34a7784ef1e4cd3aa4a8c2151006ef56a60c8b30c9a7e25cdb198036de8c27e9_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:34a7784ef1e4cd3aa4a8c2151006ef56a60c8b30c9a7e25cdb198036de8c27e9_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:60ab0ad722725d13abdede0fa569ee4ad2ec95350584dfd51c016510142f0523_amd64 as a component of Red Hat OpenShift Container Platform 4.7 | * |
Timeline
- Jun 23, 2021 CVE Published
- Mar 18, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:2130 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1945248 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1946538 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1952917 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1955319 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1956412 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1963263 issue
- https://issues.redhat.com/browse/WINC-623 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2130.json advisory
- https://access.redhat.com/security/cve/CVE-2021-25736 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-25736 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25736 advisory
- https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q advisory