SB2021061017 - OpenShift Service Mesh 2 update for servicemesh-operator
Published: June 10, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2021-3586)
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists in the servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed allowing access to all ports on these resources from any pod.
Remediation
Install update from vendor's website.