{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "unauthenticated access to Machine Config Server ignition config",
    "tracking": {
      "current_release_date": "2026-08-11T14:53:17+00:00",
      "generator": {
        "date": "2026-08-11T14:53:17+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-20238",
      "initial_release_date": "2021-02-05T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:53:17+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.19",
            "product": {
              "name": "OpenShift Container Platform 4.19",
              "product_id": "openshift-4",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 3.11.0",
            "product": {
              "name": "OpenShift Container Platform 3.11.0",
              "product_id": "openshift-enterprise-3.11",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:3"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift",
            "product": {
              "name": "atomic-openshift",
              "product_id": "atomic-openshift",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-clients",
            "product": {
              "name": "atomic-openshift-clients",
              "product_id": "atomic-openshift-clients",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-clients"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-clients-redistributable",
            "product": {
              "name": "atomic-openshift-clients-redistributable",
              "product_id": "atomic-openshift-clients-redistributable",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-clients-redistributable"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-docker-excluder",
            "product": {
              "name": "atomic-openshift-docker-excluder",
              "product_id": "atomic-openshift-docker-excluder",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-docker-excluder"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-dockerregistry",
            "product": {
              "name": "atomic-openshift-dockerregistry",
              "product_id": "atomic-openshift-dockerregistry",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-dockerregistry"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-excluder",
            "product": {
              "name": "atomic-openshift-excluder",
              "product_id": "atomic-openshift-excluder",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-excluder"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-hyperkube",
            "product": {
              "name": "atomic-openshift-hyperkube",
              "product_id": "atomic-openshift-hyperkube",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-hyperkube"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-hypershift",
            "product": {
              "name": "atomic-openshift-hypershift",
              "product_id": "atomic-openshift-hypershift",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-hypershift"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-master",
            "product": {
              "name": "atomic-openshift-master",
              "product_id": "atomic-openshift-master",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-master"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-node",
            "product": {
              "name": "atomic-openshift-node",
              "product_id": "atomic-openshift-node",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-node"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-pod",
            "product": {
              "name": "atomic-openshift-pod",
              "product_id": "atomic-openshift-pod",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-pod"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-sdn-ovs",
            "product": {
              "name": "atomic-openshift-sdn-ovs",
              "product_id": "atomic-openshift-sdn-ovs",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-sdn-ovs"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-template-service-broker",
            "product": {
              "name": "atomic-openshift-template-service-broker",
              "product_id": "atomic-openshift-template-service-broker",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-template-service-broker"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift-tests",
            "product": {
              "name": "atomic-openshift-tests",
              "product_id": "atomic-openshift-tests",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift-tests"
              }
            }
          },
          {
            "category": "product_version",
            "name": "atomic-openshift",
            "product": {
              "name": "atomic-openshift",
              "product_id": "atomic-openshift.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/atomic-openshift?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift4/ose-machine-config-rhel9-operator",
            "product": {
              "name": "openshift4/ose-machine-config-rhel9-operator",
              "product_id": "openshift4/ose-machine-config-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/ose-machine-config-rhel9-operator?repository_url=registry.redhat.io/openshift4/ose-machine-config-rhel9-operator"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift"
        },
        "product_reference": "atomic-openshift",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-clients as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-clients"
        },
        "product_reference": "atomic-openshift-clients",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-clients-redistributable as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-clients-redistributable"
        },
        "product_reference": "atomic-openshift-clients-redistributable",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-docker-excluder as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-docker-excluder"
        },
        "product_reference": "atomic-openshift-docker-excluder",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-dockerregistry as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-dockerregistry"
        },
        "product_reference": "atomic-openshift-dockerregistry",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-excluder as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-excluder"
        },
        "product_reference": "atomic-openshift-excluder",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-hyperkube as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-hyperkube"
        },
        "product_reference": "atomic-openshift-hyperkube",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-hypershift as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-hypershift"
        },
        "product_reference": "atomic-openshift-hypershift",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-master as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-master"
        },
        "product_reference": "atomic-openshift-master",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-node as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-node"
        },
        "product_reference": "atomic-openshift-node",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-pod as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-pod"
        },
        "product_reference": "atomic-openshift-pod",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-sdn-ovs as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-sdn-ovs"
        },
        "product_reference": "atomic-openshift-sdn-ovs",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-template-service-broker as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-template-service-broker"
        },
        "product_reference": "atomic-openshift-template-service-broker",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift-tests as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift-tests"
        },
        "product_reference": "atomic-openshift-tests",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "atomic-openshift.src as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:atomic-openshift.src"
        },
        "product_reference": "atomic-openshift.src",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4/ose-machine-config-rhel9-operator as a component of OpenShift Container Platform 4.19",
          "product_id": "openshift-4:openshift4/ose-machine-config-rhel9-operator"
        },
        "product_reference": "openshift4/ose-machine-config-rhel9-operator",
        "relates_to_product_reference": "openshift-4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-20238",
      "cwe": {
        "id": "CWE-306",
        "name": "Missing Authentication for Critical Function"
      },
      "discovery_date": "2020-02-07T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openshift-enterprise-3.11:atomic-openshift",
            "openshift-enterprise-3.11:atomic-openshift-clients",
            "openshift-enterprise-3.11:atomic-openshift-clients-redistributable",
            "openshift-enterprise-3.11:atomic-openshift-docker-excluder",
            "openshift-enterprise-3.11:atomic-openshift-dockerregistry",
            "openshift-enterprise-3.11:atomic-openshift-excluder",
            "openshift-enterprise-3.11:atomic-openshift-hyperkube",
            "openshift-enterprise-3.11:atomic-openshift-hypershift",
            "openshift-enterprise-3.11:atomic-openshift-master",
            "openshift-enterprise-3.11:atomic-openshift-node",
            "openshift-enterprise-3.11:atomic-openshift-pod",
            "openshift-enterprise-3.11:atomic-openshift-sdn-ovs",
            "openshift-enterprise-3.11:atomic-openshift-template-service-broker",
            "openshift-enterprise-3.11:atomic-openshift-tests",
            "openshift-enterprise-3.11:atomic-openshift.src"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Currently, there is no supported way to block or restrict the machine config server endpoint. The machine config server must be exposed to the network so that newly-provisioned machines, which have no existing configuration or state, are able to fetch their configuration. In this model, the root of trust is the certificate signing requests (CSR) endpoint, which is where the kubelet sends its certificate signing request for approval to join the cluster. Because of this, machine configs should not be used to distribute sensitive information, such as secrets and certificates.\n\nTo ensure that the machine config server endpoints, ports 22623 and 22624, are secured in bare metal scenarios, customers must configure proper network policies.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull secrets.\r\n\r\nThere are two scenarios where this data can be accessed. The first is on Baremetal, OpenStack, Ovirt, Vsphere and KubeVirt deployments which do not have a separate internal API endpoint and allow access from outside the cluster to port 22623 from the standard OpenShift API Virtual IP address.\r\n\r\nThe second is on cloud deployments when using unsupported network plugins, which do not create iptables rules that prevent to port 22623. In this scenario, the ignition config is exposed to all pods within the cluster and cannot be accessed externally.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "openshift-4:openshift4/ose-machine-config-rhel9-operator"
        ],
        "known_not_affected": [
          "openshift-enterprise-3.11:atomic-openshift",
          "openshift-enterprise-3.11:atomic-openshift-clients",
          "openshift-enterprise-3.11:atomic-openshift-clients-redistributable",
          "openshift-enterprise-3.11:atomic-openshift-docker-excluder",
          "openshift-enterprise-3.11:atomic-openshift-dockerregistry",
          "openshift-enterprise-3.11:atomic-openshift-excluder",
          "openshift-enterprise-3.11:atomic-openshift-hyperkube",
          "openshift-enterprise-3.11:atomic-openshift-hypershift",
          "openshift-enterprise-3.11:atomic-openshift-master",
          "openshift-enterprise-3.11:atomic-openshift-node",
          "openshift-enterprise-3.11:atomic-openshift-pod",
          "openshift-enterprise-3.11:atomic-openshift-sdn-ovs",
          "openshift-enterprise-3.11:atomic-openshift-template-service-broker",
          "openshift-enterprise-3.11:atomic-openshift-tests",
          "openshift-enterprise-3.11:atomic-openshift.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-20238"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20238"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-20238"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "openshift-4:openshift4/ose-machine-config-rhel9-operator"
          ]
        },
        {
          "category": "workaround",
          "details": "- If deployed on Baremetal, OpenStack, Ovirt, Vsphere or KubeVirt, check if the ignition config is accessible from outside the cluster, e.g.\n   \nhttps://api.$cluster_name.$base_domain:22623/config/worker\n  \nPrevent access to this endpoint with an external firewall or load balancer.\n\n- To protect the MCS endpoint within clusters, use a supported network plugin with OpenShift, namely: OpenShift SDN, OVN Kubernetes or kuryr.\n\n- Ensure untrusted workloads are not run with hostNetwork access.",
          "product_ids": [
            "openshift-4:openshift4/ose-machine-config-rhel9-operator"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "openshift-4:openshift4/ose-machine-config-rhel9-operator",
            "openshift-enterprise-3.11:atomic-openshift",
            "openshift-enterprise-3.11:atomic-openshift-clients",
            "openshift-enterprise-3.11:atomic-openshift-clients-redistributable",
            "openshift-enterprise-3.11:atomic-openshift-docker-excluder",
            "openshift-enterprise-3.11:atomic-openshift-dockerregistry",
            "openshift-enterprise-3.11:atomic-openshift-excluder",
            "openshift-enterprise-3.11:atomic-openshift-hyperkube",
            "openshift-enterprise-3.11:atomic-openshift-hypershift",
            "openshift-enterprise-3.11:atomic-openshift-master",
            "openshift-enterprise-3.11:atomic-openshift-node",
            "openshift-enterprise-3.11:atomic-openshift-pod",
            "openshift-enterprise-3.11:atomic-openshift-sdn-ovs",
            "openshift-enterprise-3.11:atomic-openshift-template-service-broker",
            "openshift-enterprise-3.11:atomic-openshift-tests",
            "openshift-enterprise-3.11:atomic-openshift.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "openshift-4:openshift4/ose-machine-config-rhel9-operator",
            "openshift-enterprise-3.11:atomic-openshift",
            "openshift-enterprise-3.11:atomic-openshift-clients",
            "openshift-enterprise-3.11:atomic-openshift-clients-redistributable",
            "openshift-enterprise-3.11:atomic-openshift-docker-excluder",
            "openshift-enterprise-3.11:atomic-openshift-dockerregistry",
            "openshift-enterprise-3.11:atomic-openshift-excluder",
            "openshift-enterprise-3.11:atomic-openshift-hyperkube",
            "openshift-enterprise-3.11:atomic-openshift-hypershift",
            "openshift-enterprise-3.11:atomic-openshift-master",
            "openshift-enterprise-3.11:atomic-openshift-node",
            "openshift-enterprise-3.11:atomic-openshift-pod",
            "openshift-enterprise-3.11:atomic-openshift-sdn-ovs",
            "openshift-enterprise-3.11:atomic-openshift-template-service-broker",
            "openshift-enterprise-3.11:atomic-openshift-tests",
            "openshift-enterprise-3.11:atomic-openshift.src"
          ]
        }
      ],
      "title": "unauthenticated access to Machine Config Server ignition config"
    }
  ]
}