CVE-2021-4125: Input Validation
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-4125?
CVE-2021-4125 is a vulnerability that was found in the OpenShift metering hive containers, where the original fix for log4j CVE-2021-44228 and CVE-2021-45046 was incomplete.
How severe is CVE-2021-4125?
CVE-2021-4125 has a severity rating of 8.1 (critical).
Which software is affected by CVE-2021-4125?
The OpenShift metering hive container images in OpenShift versions 4.8, 4.7, and 4.6 are affected by CVE-2021-4125.
How can I fix the CVE-2021-4125 vulnerability?
To fix the CVE-2021-4125 vulnerability, you should update your OpenShift Metering hive container images to include the complete fix for log4j CVE-2021-44228 and CVE-2021-45046.
Where can I find more information about CVE-2021-4125?
You can find more information about CVE-2021-4125 on the Red Hat Security Advisory page: [link](https://access.redhat.com/security/cve/CVE-2021-4125).