Openshift Machine-Config-Operator vulnerabilities
2 known vulnerabilities affecting openshift/machine-config-operator.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2021-20238LOWCVSS 3.7vaffecting versions up to, including ose-machine-config-operator-container-v4.9.02022-04-01
CVE-2021-20238 [LOW] CWE-287 CVE-2021-20238: It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Se
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull secrets. There are two scenarios whe
cvelistv5nvd
CVE-2020-35514HIGHCVSS 7.0vUnspecified2021-06-02
CVE-2020-35514 [HIGH] CWE-266 CVE-2020-35514: An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This fl
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest threat from this vulnerability is
cvelistv5nvd