{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "can deploy specified image to any namespace",
    "tracking": {
      "current_release_date": "2026-08-11T14:55:31+00:00",
      "generator": {
        "date": "2026-08-11T14:55:31+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-3495",
      "initial_release_date": "2021-05-11T19:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:55:31+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "OpenShift Service Mesh maistra-1.1.3",
            "product": {
              "name": "OpenShift Service Mesh maistra-1.1.3",
              "product_id": "maistra-1.1.3",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:service_mesh:1"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Service Mesh OSSM 2.0.0",
            "product": {
              "name": "OpenShift Service Mesh OSSM 2.0.0",
              "product_id": "ossm-2.0::el8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:service_mesh:2.0::el8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift-service-mesh/kiali-rhel7-operator",
            "product": {
              "name": "openshift-service-mesh/kiali-rhel7-operator",
              "product_id": "openshift-service-mesh/kiali-rhel7-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/kiali-rhel7-operator?repository_url=registry.redhat.io/openshift-service-mesh/kiali-rhel7-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift-service-mesh/kiali-rhel8-operator",
            "product": {
              "name": "openshift-service-mesh/kiali-rhel8-operator",
              "product_id": "openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1",
              "product_identification_helper": {
                "purl": "pkg:oci/kiali-rhel8-operator@1.24.7-1?repository_url=registry.redhat.io/openshift-service-mesh/kiali-rhel8-operator"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift-service-mesh/kiali-rhel7-operator as a component of OpenShift Service Mesh maistra-1.1.3",
          "product_id": "maistra-1.1.3:openshift-service-mesh/kiali-rhel7-operator"
        },
        "product_reference": "openshift-service-mesh/kiali-rhel7-operator",
        "relates_to_product_reference": "maistra-1.1.3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1 as a component of OpenShift Service Mesh OSSM 2.0.0",
          "product_id": "ossm-2.0::el8:openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1"
        },
        "product_reference": "openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1",
        "relates_to_product_reference": "ossm-2.0::el8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3495",
      "cwe": {
        "id": "CWE-281",
        "name": "Improper Preservation of Permissions"
      },
      "discovery_date": "2021-04-06T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "In regards to the ServiceMesh `openshift-service-mesh/kiali-rhel7` container, it has been superseded by the `openshift-service-mesh/kiali-rhel8` container and is no longer supported.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "An incorrect access control flaw was found in the kiali-operator. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability and deploy a given image to anywhere in the cluster, potentially gaining access to privileged service account tokens. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "ossm-2.0::el8:openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1"
        ],
        "known_affected": [
          "maistra-1.1.3:openshift-service-mesh/kiali-rhel7-operator"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-3495"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3495"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3495"
        }
      ],
      "remediations": [
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "maistra-1.1.3:openshift-service-mesh/kiali-rhel7-operator"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2021-05-11T23:41:10+00:00",
          "details": "Apply advisory RHSA-2021:1544 as per vendors instructions.",
          "product_ids": [
            "ossm-2.0::el8:openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:1544"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 8.8,
            "baseSeverity": "HIGH"
          },
          "products": [
            "maistra-1.1.3:openshift-service-mesh/kiali-rhel7-operator",
            "ossm-2.0::el8:openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "maistra-1.1.3:openshift-service-mesh/kiali-rhel7-operator",
            "ossm-2.0::el8:openshift-service-mesh/kiali-rhel8-operator-0:1.24.7-1"
          ]
        }
      ],
      "title": "can deploy specified image to any namespace"
    }
  ]
}