← Back

CVE-2021-3684

nvd nist
Published: Mar 24, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

Affected (2)

2 products
Openshift Assisted Installer
Openshift Container Platform
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.25.3
Version 4.6
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0

Timeline

No history available yet.