CVE-2021-3917
published 2022-08-23CVE-2021-3917: A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.22%
12.9th percentile
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | coreos-installer | < 0.10.0 | 0.10.0 |
| redhat | coreos-installer | — | — |
| redhat | coreos-installer | >= 0 < 0.10.0 | 0.10.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
osv·2021-11-08
CVE-2021-3917 [MEDIUM] coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
### Impact
On systems installed with coreos-installer before 0.10.0, the user-provided Ignition config was written to `/boot/ignition/config.ign` with world-readable permissions, granting unprivileged users access to any secrets included in the config.
Default configurations of Fedora CoreOS and RHEL CoreOS do not include any unprivileged user accounts. In addition, instances launched from a cloud image, and systems provisioned with the `ignition.config.url` kernel argument, do not use the `config.ign` file and are unaffected.
### Patches
coreos-installer 0.10.0 and later [writes](https://github.com/coreos/coreos-installer/pull/571) the Ignition config with restricted permissions.
### Workarounds
On Fe
GHSA
coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
ghsa·2021-11-08
CVE-2021-3917 [MEDIUM] CWE-276 coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
coreos-installer < 0.10.0 writes world-readable Ignition config to installed system
### Impact
On systems installed with coreos-installer before 0.10.0, the user-provided Ignition config was written to `/boot/ignition/config.ign` with world-readable permissions, granting unprivileged users access to any secrets included in the config.
Default configurations of Fedora CoreOS and RHEL CoreOS do not include any unprivileged user accounts. In addition, instances launched from a cloud image, and systems provisioned with the `ignition.config.url` kernel argument, do not use the `config.ign` file and are unaffected.
### Patches
coreos-installer 0.10.0 and later [writes](https://github.com/coreos/coreos-installer/pull/571) the Ignition config with restricted permissions.
### Workarounds
On Fe
Red Hat
coreos-installer: restrict access permissions on /boot/ignition{,/config.ign}
vendor_redhat·2021-07-07·CVSS 5.5
CVE-2021-3917 [MEDIUM] CWE-276 coreos-installer: restrict access permissions on /boot/ignition{,/config.ign}
coreos-installer: restrict access permissions on /boot/ignition{,/config.ign}
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
Package: coreos-installer (Red Hat Enterprise Linux 8) - Fix deferred
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3917https://bugzilla.redhat.com/show_bug.cgi?id=2018478https://github.com/coreos/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0chttps://github.com/coreos/fedora-coreos-tracker/issues/889https://access.redhat.com/security/cve/CVE-2021-3917https://bugzilla.redhat.com/show_bug.cgi?id=2018478https://github.com/coreos/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0chttps://github.com/coreos/fedora-coreos-tracker/issues/889
2022-08-23
Published