It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.
Patches: https://github.com/kube-reporting/hive/pull/71 https://github.com/kube-reporting/hive/pull/72 https://github.com/kube-reporting/hive/pull/73
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.8 Via RHSA-2021:5183 https://access.redhat.com/errata/RHSA-2021:5183
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2021:5184 https://access.redhat.com/errata/RHSA-2021:5184
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2021:5186 https://access.redhat.com/errata/RHSA-2021:5186
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-4125