CVE-2021-4125

Description

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.

Statement

This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6. The below previously shipped advisories were incomplete:

https://access.redhat.com/errata/RHSA-2021:5108

https://access.redhat.com/errata/RHSA-2021:5107

https://access.redhat.com/errata/RHSA-2021:5106

For the complete fix, customers should upgrade to the images shipped in these advisories:

4.8.24: https://access.redhat.com/errata/RHSA-2021:5183

4.7.40: https://access.redhat.com/errata/RHSA-2021:5184

4.6.52 https://access.redhat.com/errata/RHSA-2021:5186

The OpenShift Metering hive container images were deprecated in OpenShift 4.8, and not shipped in 4.9 or later.

Mitigation

Please follow the Mitigation advice for the original CVEs.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score8.18.1N/A
Attack VectorNetworkNetworkN/A
Attack ComplexityHighHighN/A
Privileges RequiredNoneNoneN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityHighHighN/A
Integrity ImpactHighHighN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

Want to get errata notifications? Sign up here.