CVE-2022-1706
published 2022-05-17CVE-2022-1706: A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.23%
65.9th percentile
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coreos | ignition | — | — |
| debian | ignition | < ignition 2.14.0+ds1-1 (bookworm) | ignition 2.14.0+ds1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | coreos_ignition | >= 0 < 2.14.0 | 2.14.0 |
| github.com | coreos_ignition_v2 | >= 0 < 2.14.0 | 2.14.0 |
| inductiveautomation | ignition | >= 0 < 2.14.0+ds1-1 | 2.14.0+ds1-1 |
| inductiveautomation | ignition | >= 0 < 2.14.0+ds1-1 | 2.14.0+ds1-1 |
| inductiveautomation | ignition | >= 0 < 2.14.0+ds1-1 | 2.14.0+ds1-1 |
| redhat | enterprise_linux | — | — |
| redhat | ignition | < 2.14.0 | 2.14.0 |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Ignition config accessible to unprivileged software on VMware in github.com/coreos/ignition
osv·2024-08-21
CVE-2022-1706 Ignition config accessible to unprivileged software on VMware in github.com/coreos/ignition
Ignition config accessible to unprivileged software on VMware in github.com/coreos/ignition
Ignition config accessible to unprivileged software on VMware in github.com/coreos/ignition
OSV
Ignition config accessible to unprivileged software on VMware
osv·2022-05-25
CVE-2022-1706 [MEDIUM] Ignition config accessible to unprivileged software on VMware
Ignition config accessible to unprivileged software on VMware
### Impact
Unprivileged software in VMware VMs, including software running in unprivileged containers, can retrieve an Ignition config stored in a hypervisor guestinfo variable or OVF environment. If the Ignition config contains secrets, this can result in the compromise of sensitive information.
### Patches
Ignition 2.14.0 and later [adds](https://github.com/coreos/ignition/pull/1350) a new systemd service, `ignition-delete-config.service`, that deletes the Ignition config from supported hypervisors (currently VMware and VirtualBox) during the first boot. This ensures that unprivileged software cannot retrieve the Ignition config from the hypervisor.
If you have external tooling that requires the Ignition config to remain ac
GHSA
Ignition config accessible to unprivileged software on VMware
ghsa·2022-05-25
CVE-2022-1706 [MEDIUM] CWE-200 Ignition config accessible to unprivileged software on VMware
Ignition config accessible to unprivileged software on VMware
### Impact
Unprivileged software in VMware VMs, including software running in unprivileged containers, can retrieve an Ignition config stored in a hypervisor guestinfo variable or OVF environment. If the Ignition config contains secrets, this can result in the compromise of sensitive information.
### Patches
Ignition 2.14.0 and later [adds](https://github.com/coreos/ignition/pull/1350) a new systemd service, `ignition-delete-config.service`, that deletes the Ignition config from supported hypervisors (currently VMware and VirtualBox) during the first boot. This ensures that unprivileged software cannot retrieve the Ignition config from the hypervisor.
If you have external tooling that requires the Ignition config to remain ac
OSV
CVE-2022-1706: A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products
osv·2022-05-17·CVSS 6.5
CVE-2022-1706 [MEDIUM] CVE-2022-1706: A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Red Hat
ignition: configs are accessible from unprivileged containers in VMs running on VMware products
vendor_redhat·2022-05-04·CVSS 6.5
CVE-2022-1706 [MEDIUM] CWE-863 ignition: configs are accessible from unprivileged containers in VMs running on VMware products
ignition: configs are accessible from unprivileged containers in VMs running on VMware products
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
A vulnerability was found in Ignition, where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets.
Statement: RHCOS may be less impacted than other distros since OCP's default Ignition config only
Debian
CVE-2022-1706: ignition - A vulnerability was found in Ignition where ignition configs are accessible from...
vendor_debian·2022·CVSS 6.5
CVE-2022-1706 [MEDIUM] CVE-2022-1706: ignition - A vulnerability was found in Ignition where ignition configs are accessible from...
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Scope: local
bookworm: resolved (fixed in 2.14.0+ds1-1)
forky: resolved (fixed in 2.14.0+ds1-1)
sid: resolved (fixed in 2.14.0+ds1-1)
trixie: resolved (fixed in 2.14.0+ds1-1)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2082274https://github.com/coreos/ignition/commit/4b70b44b430ecf8377a276e89b5acd3a6957d4eahttps://github.com/coreos/ignition/issues/1300https://github.com/coreos/ignition/issues/1315https://github.com/coreos/ignition/pull/1350https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LY7LKGMQMXV6DGD263YQHNSLOJJ5VLV5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NP765L7TJI7CD4XVOHUWZVRYRH3FYBOR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5QQXRGQKTN4YX2ZF3GQNEBDEOKJGCN3/https://bugzilla.redhat.com/show_bug.cgi?id=2082274https://github.com/coreos/ignition/commit/4b70b44b430ecf8377a276e89b5acd3a6957d4eahttps://github.com/coreos/ignition/issues/1300https://github.com/coreos/ignition/issues/1315https://github.com/coreos/ignition/pull/1350https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LY7LKGMQMXV6DGD263YQHNSLOJJ5VLV5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NP765L7TJI7CD4XVOHUWZVRYRH3FYBOR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5QQXRGQKTN4YX2ZF3GQNEBDEOKJGCN3/
2022-05-17
Published