VDB
RHSA-2023%3A1328
RHSA-2023%3A1328
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in Mongo. Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshaling Go objects into BSON. This flaw allows a malicious user to use a Go object with a specific string to inject additional fields into marshaled documents.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-clusterresourceoverride-rhel8@sha256:7ac8160b4d5707a1a3b35c6a628723969828fe0081994e8de578ef1325604272_s390x as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-csi-external-resizer@sha256:a9ec890aebfb138c00fc49125cd3f3cc1b6956956769dafd8f870c112ae86ae4_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-csi-external-resizer@sha256:a9ec890aebfb138c00fc49125cd3f3cc1b6956956769dafd8f870c112ae86ae4_arm64, openshift4/ose-csi-external-resizer@sha256:a9ec890aebfb138c00fc49125cd3f3cc1b6956956769dafd8f870c112ae86ae4_arm64, openshift4/ose-csi-external-resizer@sha256:a9ec890aebfb138c00fc49125cd3f3cc1b6956956769dafd8f870c112ae86ae4_arm64 |
| Red Hat | openshift4/metallb-rhel8-operator@sha256:eb2886bcb12d54453c7fcb9650e7f9ae06be9ad12aad8f05286f7206d3adef73_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:5a939967d8624a9ecc879eb557cfb985666e52ed20747ad0ed68959669b3cf23_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:5a939967d8624a9ecc879eb557cfb985666e52ed20747ad0ed68959669b3cf23_arm64 |
| Red Hat | openshift4/ose-descheduler@sha256:fd561cc256baed27638092ddd40b2216bd3c62e140ad4a874881199d5c15dc7a_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-descheduler@sha256:fd561cc256baed27638092ddd40b2216bd3c62e140ad4a874881199d5c15dc7a_amd64, *, openshift4/ose-descheduler@sha256:fd561cc256baed27638092ddd40b2216bd3c62e140ad4a874881199d5c15dc7a_amd64 |
| Red Hat | openshift4/ose-metallb-operator-bundle@sha256:f1bc536c642deb1aee8692de34dfaeef185164508d50648a5066dc07503cc8f3_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-metallb-operator-bundle@sha256:f1bc536c642deb1aee8692de34dfaeef185164508d50648a5066dc07503cc8f3_amd64, openshift4/ose-metallb-operator-bundle@sha256:f1bc536c642deb1aee8692de34dfaeef185164508d50648a5066dc07503cc8f3_amd64, * |
| Red Hat | openshift4/metallb-rhel8-operator@sha256:96962a001d4dfd16a88c77bf948fb2a673cb1404a3c901dd27d16c90151b267c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-csi-node-driver-registrar-rhel8@sha256:5a85eedf898ca5ce364c2b80557e0aaa3719c75a8e3a4e040f8d89bc594c0c50_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/ose-csi-node-driver-registrar-rhel8@sha256:5a85eedf898ca5ce364c2b80557e0aaa3719c75a8e3a4e040f8d89bc594c0c50_arm64, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:6a1b18e7e9a341a37f4fbf1ab2b55c0e740401b77ec91357cbe468f5f6cfbdf8_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:6a1b18e7e9a341a37f4fbf1ab2b55c0e740401b77ec91357cbe468f5f6cfbdf8_arm64, openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:6a1b18e7e9a341a37f4fbf1ab2b55c0e740401b77ec91357cbe468f5f6cfbdf8_arm64, * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:04776655db16475e8961e182dc7ae8113a1e5498fb957d69470116c33c3aa102_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:04776655db16475e8961e182dc7ae8113a1e5498fb957d69470116c33c3aa102_arm64, *, openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:04776655db16475e8961e182dc7ae8113a1e5498fb957d69470116c33c3aa102_arm64 |
| Red Hat | openshift4/ingress-node-firewall@sha256:cf5fa06406e38936d52d4e965f8007e6be530ce2db228ca74a7e13b2998cbddd_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ingress-node-firewall@sha256:cf5fa06406e38936d52d4e965f8007e6be530ce2db228ca74a7e13b2998cbddd_arm64, *, * |
| Red Hat | openshift-tech-preview/metallb-rhel8@sha256:ab2c145d92489d1f01e7ad0d1fa1be96dcbe73e718cd3ce64f55057fd3fb3871_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift-tech-preview/metallb-rhel8@sha256:ab2c145d92489d1f01e7ad0d1fa1be96dcbe73e718cd3ce64f55057fd3fb3871_amd64, openshift-tech-preview/metallb-rhel8@sha256:ab2c145d92489d1f01e7ad0d1fa1be96dcbe73e718cd3ce64f55057fd3fb3871_amd64, openshift-tech-preview/metallb-rhel8@sha256:ab2c145d92489d1f01e7ad0d1fa1be96dcbe73e718cd3ce64f55057fd3fb3871_amd64 |
| Red Hat | openshift4/ose-local-storage-diskmaker@sha256:31e793306501639506a4de10d9f3774f92b7fd907e3fb98dd9da01c27b27a2a6_s390x as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-local-storage-diskmaker@sha256:31e793306501639506a4de10d9f3774f92b7fd907e3fb98dd9da01c27b27a2a6_s390x, openshift4/ose-local-storage-diskmaker@sha256:31e793306501639506a4de10d9f3774f92b7fd907e3fb98dd9da01c27b27a2a6_s390x, openshift4/ose-local-storage-diskmaker@sha256:31e793306501639506a4de10d9f3774f92b7fd907e3fb98dd9da01c27b27a2a6_s390x |
| Red Hat | openshift4/ose-metallb-operator-bundle@sha256:f1bc536c642deb1aee8692de34dfaeef185164508d50648a5066dc07503cc8f3_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-clusterresourceoverride-operator-bundle@sha256:388e3f7c83c49e5c0d15a9f2aeee720b2aa6c774eea5026d9e3cc801c79daeec_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-clusterresourceoverride-operator-bundle@sha256:388e3f7c83c49e5c0d15a9f2aeee720b2aa6c774eea5026d9e3cc801c79daeec_amd64, openshift4/ose-clusterresourceoverride-operator-bundle@sha256:388e3f7c83c49e5c0d15a9f2aeee720b2aa6c774eea5026d9e3cc801c79daeec_amd64, openshift4/ose-clusterresourceoverride-operator-bundle@sha256:388e3f7c83c49e5c0d15a9f2aeee720b2aa6c774eea5026d9e3cc801c79daeec_amd64 |
| Red Hat | openshift4/ose-sriov-network-device-plugin@sha256:9a3afd6212a1bd94f64a87a6f87a12d4ac85e74abad01730c85fedf18dd0325e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, openshift4/ose-sriov-network-device-plugin@sha256:9a3afd6212a1bd94f64a87a6f87a12d4ac85e74abad01730c85fedf18dd0325e_amd64 |
| Red Hat | openshift4/ose-csi-external-resizer@sha256:a9ec890aebfb138c00fc49125cd3f3cc1b6956956769dafd8f870c112ae86ae4_arm64 as a component of Red Hat OpenShift Container Platform 4.13 | *, openshift4/ose-csi-external-resizer@sha256:a9ec890aebfb138c00fc49125cd3f3cc1b6956956769dafd8f870c112ae86ae4_arm64, * |
| Red Hat | openshift4/ose-sriov-network-webhook@sha256:8dec05998536e8b165bb9b045129086baa9e2df75a7fdd108b28123c6d6cbb4f_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-sriov-network-webhook@sha256:8dec05998536e8b165bb9b045129086baa9e2df75a7fdd108b28123c6d6cbb4f_amd64, *, openshift4/ose-sriov-network-webhook@sha256:8dec05998536e8b165bb9b045129086baa9e2df75a7fdd108b28123c6d6cbb4f_amd64 |
| Red Hat | openshift4/kubernetes-nmstate-rhel8-operator@sha256:b56f788f9a30e62ebd9c99ed1d0c0b86d61bb4f65dffd910857f9164559e7dae_s390x as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-sriov-infiniband-cni@sha256:ee7e152f360f26eba88f2fce09f4292c887911d50d127744d19a2bf545160f7e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-sriov-infiniband-cni@sha256:ee7e152f360f26eba88f2fce09f4292c887911d50d127744d19a2bf545160f7e_amd64, openshift4/ose-sriov-infiniband-cni@sha256:ee7e152f360f26eba88f2fce09f4292c887911d50d127744d19a2bf545160f7e_amd64, openshift4/ose-sriov-infiniband-cni@sha256:ee7e152f360f26eba88f2fce09f4292c887911d50d127744d19a2bf545160f7e_amd64 |
…and 338 more
Timeline
- May 18, 2023 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 25, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2023:1328 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1971033 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2100495 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2161274 issue
- https://issues.redhat.com/browse/OCPBUGS-10561 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1328.json advisory
- https://access.redhat.com/security/cve/CVE-2021-20329 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-20329 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-20329 advisory
- https://github.com/advisories/GHSA-f6mq-5m25-4r72 advisory
- https://github.com/mongodb/mongo-go-driver/releases/tag/v1.5.1 advisory
- https://access.redhat.com/security/cve/CVE-2021-38561 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-38561 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-38561 advisory
- https://pkg.go.dev/vuln/GO-2021-0113 advisory
- https://access.redhat.com/security/cve/CVE-2022-41717 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-41717 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-41717 advisory
- https://go.dev/cl/455635 advisory
…and 4 more