RHSA-2021:5186CriticalCVSS 8.1
Red Hat Security Advisory: OpenShift Container Platform 4.6.52 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-4104 — log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender CVE-2021-4125 — kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2021:5186
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2021-009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031667
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2033121
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_5186.json