CVE-2021-4047: Input Validation
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
Other sources
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package. However, it was found that a patch for one of these CVEs was missing, CVE-2021-39242. This issue was only found in OpenShift 4.9, it does not apply to earlier versions of OpenShift, other Red Hat products or to upstream haproxy.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4047?
CVE-2021-4047 has been classified with a medium severity level due to its impact on the haproxy package in Red Hat OpenShift 4.9.
Which versions of OpenShift are affected by CVE-2021-4047?
CVE-2021-4047 specifically affects Red Hat OpenShift version 4.9.
How do I fix CVE-2021-4047?
The recommended fix for CVE-2021-4047 is to apply the latest available patches and updates for Red Hat OpenShift 4.9.
Does CVE-2021-4047 include a patch?
CVE-2021-4047 does not include a patch as it relates to a previously missing patch for CVE-2021-39242.
What is the impact of CVE-2021-4047 on my system?
The impact of CVE-2021-4047 may include potential vulnerabilities in the haproxy package, which could be exploited if not addressed.