CVE-2021-3684Log File Information Exposure in Openshift Assisted-installer

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 64.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24

Description

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Also affects: Openshift Container Platform 4.6

Patches

🔴Vulnerability Details

3
GHSA
OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs2023-03-24
CVEList
CVE-2021-3684: A vulnerability was found in OpenShift Assisted Installer2023-03-24
OSV
OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs2023-03-24

📋Vendor Advisories

1
Red Hat
assisted-installer: Image Pull Secret leaked through log files2022-10-19
CVE-2021-3684 — Log File Information Exposure | cvebase