VDB
RHSA-2021%3A3001
RHSA-2021%3A3001
PUBLISHED
CVSS 7.199999809265137 HIGH
An improper limitation of path name flaw was found in containernetworking/cni. When specifying the plugin to load in the `type` field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as `reboot`. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:d6d2bcc5bb80900b446c020d8d800bb3831e7bd247f0b0363291f09b908b4d9c_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4-wincw/windows-machine-config-operator-bundle@sha256:d6d2bcc5bb80900b446c020d8d800bb3831e7bd247f0b0363291f09b908b4d9c_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:519418c1b39d6c73761e631ca7133035f210878e00711c2c841c564130ddf13e_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:519418c1b39d6c73761e631ca7133035f210878e00711c2c841c564130ddf13e_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-operator-bundle@sha256:d6d2bcc5bb80900b446c020d8d800bb3831e7bd247f0b0363291f09b908b4d9c_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4-wincw/windows-machine-config-operator-bundle@sha256:d6d2bcc5bb80900b446c020d8d800bb3831e7bd247f0b0363291f09b908b4d9c_amd64 |
| Red Hat | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:519418c1b39d6c73761e631ca7133035f210878e00711c2c841c564130ddf13e_amd64 as a component of Red Hat OpenShift Container Platform 4.8 | openshift4-wincw/windows-machine-config-rhel8-operator@sha256:519418c1b39d6c73761e631ca7133035f210878e00711c2c841c564130ddf13e_amd64 |
Timeline
- Aug 3, 2021 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 30, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:3001 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1905950 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1919391 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1930791 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1939968 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1948037 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1952914 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1953692 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1971745 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1983153 issue
- https://issues.redhat.com/browse/WINC-618 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3001.json advisory
- https://access.redhat.com/security/cve/CVE-2021-20206 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-20206 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-20206 advisory