CVE-2021-3636

Summary

CVECVE-2021-3636
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2021-07-30 20:15:00 UTC
Updated2023-11-07 03:38:00 UTC
DescriptionIt was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclusion of additional CAs in this certificate would allow an attacker that compromises any of the additional CAs to masquerade as a trusted in-cluster service.

Risk And Classification

Problem Types: CWE-287

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Redhat Openshift All All All All

References

ReferenceSourceLinkTags
1978621 – (CVE-2021-3636) CVE-2021-3636 openshift: Injected service-ca.crt incorrectly contains additional internal CAs MISC bugzilla.redhat.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 239525 Red Hat Update for OpenShift Container Platform 4.8.2 (RHSA-2021:2437)
  • 375759 Putty Multiple Security Vulnerabilities
  • 375787 Nagios XI Multiple Vulnerabilities
  • 770074 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021:2437)
  • 770111 Red Hat OpenShift Container Platform 4.8 Security Update (RHSA-2021-2437)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report