CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:redhat:openshift_assisted_installer:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:22

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - Issue Tracking, Patch, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - Issue Tracking, Patch, Vendor Advisory
References () https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - Patch () https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - Patch
References () https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - Patch () https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - Patch

03 Apr 2023, 17:56

Type Values Removed Values Added
References (MISC) https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - (MISC) https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - Patch
References (MISC) https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - (MISC) https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - Patch
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - Issue Tracking, Patch, Vendor Advisory
First Time Redhat enterprise Linux
Redhat openshift Container Platform
Redhat openshift Assisted Installer
Redhat
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:redhat:openshift_assisted_installer:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
CWE CWE-532

24 Mar 2023, 20:38

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-24 20:15

Updated : 2024-11-21 06:22


NVD link : CVE-2021-3684

Mitre link : CVE-2021-3684

CVE.ORG link : CVE-2021-3684


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_assisted_installer
  • openshift_container_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File