CVE-2021-43979 describes a concurrency issue in Styra Open Policy Agent (OPA) Gatekeeper through version 3.7.0, where the data replication mechanism can lead to inconsistent access control decisions. This vulnerability, rated Medium with a CVSS score of 5.3, arises because OPA/Gatekeeper processes requests before data replication is complete, potentially causing a policy bypass due to discrepancies between replicated and actual cluster states. There is no evidence of active exploitation, public exploit code, or significant community discussion, and the vendor disputes its classification as a vulnerability due to the eventual consistency model of Kubernetes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.7.0CPE matchmatch criteria | cpe:2.3:a:openpolicyagent:gatekeeper:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.