Redhat Coreos-Installer vulnerabilities
2 known vulnerabilities affecting redhat/coreos-installer.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-20319P3HIGHCVSS 7.8fixed in 0.10.1vAffects coreos-installer before v0.10.1, Fixed in v0.10.1.2022-03-04
CVE-2021-20319 [HIGH] CWE-347 CVE-2021-20319: An improper signature verification vulnerability was found in coreos-installer. A specially crafted
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the
ghsanvdosv
CVE-2021-3917P4MEDIUMCVSS 5.5fixed in 0.10.0vFixed in coreos-installer 0.10.02022-08-23
CVE-2021-3917 [MEDIUM] CWE-276 CVE-2021-3917: A flaw was found in the coreos-installer, where it writes the Ignition config to the target system w
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
ghsanvdosv