CVE-2021-4125
Estado: ModificadaAlta (8.1)—
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.49%
- Percentil entre todas las CVEs puntuadas: 73
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-502
Referencias
- https://access.redhat.com/security/cve/CVE-2021-4125
- https://access.redhat.com/security/cve/CVE-2021-44228
- https://access.redhat.com/security/cve/CVE-2021-45046
- https://bugzilla.redhat.com/show_bug.cgi?id=2033121
- https://github.com/kube-reporting/hive/pull/71
- https://github.com/kube-reporting/hive/pull/72
- https://github.com/kube-reporting/hive/pull/73
- https://access.redhat.com/security/cve/CVE-2021-4125
- https://access.redhat.com/security/cve/CVE-2021-44228
- https://access.redhat.com/security/cve/CVE-2021-45046
- https://bugzilla.redhat.com/show_bug.cgi?id=2033121
- https://github.com/kube-reporting/hive/pull/71
- https://github.com/kube-reporting/hive/pull/72
- https://github.com/kube-reporting/hive/pull/73
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-4125",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "kube-reporting/hive",
"versions": [
{
"status": "affected",
"version": "Fixed in v4.8, v4.7 and v4.6"
}
]
}
]
}
],
"published": "2022-08-24T16:15:09.483",
"references": [
{
"url": "https://access.redhat.com/security/cve/CVE-2021-4125",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2021-44228",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2021-45046",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2033121",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/kube-reporting/hive/pull/71",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/kube-reporting/hive/pull/72",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/kube-reporting/hive/pull/73",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2021-4125",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2021-44228",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2021-45046",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2033121",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/kube-reporting/hive/pull/71",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/kube-reporting/hive/pull/72",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/kube-reporting/hive/pull/73",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-502"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6."
},
{
"lang": "es",
"value": "Se ha detectado que la corrección original para log4j CVE-2021-44228 y CVE-2021-45046 en los contenedores hive de medición de OpenShift estaba incompleta, ya que no fueron eliminados todos los archivos JndiLookup.class. Esta CVE sólo es aplicada a imágenes de contenedores hive de OpenShift Metering, enviadas en OpenShift versiones 4.8, 4.7 y 4.6."
}
],
"lastModified": "2026-06-17T04:19:04.587",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F788739F-0B28-4751-9A4E-E0C5B7F79613",
"versionEndExcluding": "4.6.52",
"versionStartIncluding": "4.6.0"
},
{
"criteria": "cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C2659CC-7CA5-49B2-901D-DE3E1693C3E3",
"versionEndExcluding": "4.7.40",
"versionStartIncluding": "4.7.0"
},
{
"criteria": "cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE4321F9-4224-47EF-9853-9C891EFB86DD",
"versionEndExcluding": "4.8.24",
"versionStartIncluding": "4.8.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}