CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:redhat:openshift_assisted_installer:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:22

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - Issue Tracking, Patch, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - Issue Tracking, Patch, Vendor Advisory
References () https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - Patch () https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - Patch
References () https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - Patch () https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - Patch

Information

Published : 2023-03-24 20:15

Updated : 2024-11-21 06:22


NVD link : CVE-2021-3684

Mitre link : CVE-2021-3684

CVE.ORG link : CVE-2021-3684


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_assisted_installer
  • openshift_container_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File