5.5
CVE-2021-3684
- EPSS 0.04%
- Published 24.03.2023 20:15:08
- Last modified 21.11.2024 06:22:09
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Data is provided by the National Vulnerability Database (NVD)
Redhat ≫ Openshift Assisted Installer Version < 1.0.25.3
Redhat ≫ Openshift Container Platform Version4.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.1 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.