RHSA-2021:2438MediumCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.8.2 bug fix and security update

Published
July 27, 2021
Last Modified
May 29, 2026

🔗 CVE IDs covered (27)

📋 Description

CVE-2016-2183 — SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) CVE-2020-7774 — nodejs-y18n: prototype pollution vulnerability CVE-2020-15106 — etcd: Large slice causes panic in decodeRecord method CVE-2020-15112 — etcd: DoS in wal/wal.go CVE-2020-15113 — etcd: directories created via os.MkdirAll are not checked for permissions CVE-2020-15114 — etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS CVE-2020-15136 — etcd: no authentication is performed against endpoints provided in the --endpoints flag CVE-2020-26160 — jwt-go: access restriction bypass vulnerability CVE-2020-28469 — nodejs-glob-parent: Regular expression denial of service CVE-2020-28500 — nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions CVE-2020-28852 — golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag CVE-2021-3114 — golang: crypto/elliptic: incorrect operations on the P-224 curve CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-20206 — containernetworking-cni: Arbitrary path injection via type field in CNI configuration CVE-2021-20291 — containers/storage: DoS via malicious image CVE-2021-22133 — go.elastic.co/apm: leaks sensitive HTTP headers during panic CVE-2021-23337 — nodejs-lodash: command injection via template CVE-2021-23362 — nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl() CVE-2021-23368 — nodejs-postcss: Regular expression denial of service during source map parsing CVE-2021-23382 — nodejs-postcss: ReDoS via getAnnotationURL() and loadAnnotation() in lib/previous-map.js CVE-2021-26539 — sanitize-html: improper handling of internationalized domain name (IDN) can lead to bypass hostname whitelist validation CVE-2021-26540 — sanitize-html: improper validation of hostnames set by the "allowedIframeHostnames" option can lead to bypass hostname whitelist for iframe element CVE-2021-27292 — nodejs-ua-parser-js: ReDoS via malicious User-Agent header CVE-2021-28092 — nodejs-is-svg: ReDoS via malicious string CVE-2021-29059 — nodejs-is-svg: Regular expression denial of service if the application is provided and checks a crafted invalid SVG string CVE-2021-29622 — prometheus: open redirect under the /new endpoint CVE-2021-33194 — golang: x/net/html: infinite loop in ParseFragment

🔗 References (1724)