CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:redhat:openshift_assisted_installer:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

03 Apr 2023, 17:56

Type Values Removed Values Added
CWE CWE-532
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Redhat openshift Container Platform
Redhat
Redhat openshift Assisted Installer
Redhat enterprise Linux
CPE cpe:2.3:a:redhat:openshift_assisted_installer:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
References (MISC) https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - (MISC) https://github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4 - Patch
References (MISC) https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - (MISC) https://github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a - Patch
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1985962 - Issue Tracking, Patch, Vendor Advisory

24 Mar 2023, 20:38

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-24 20:15

Updated : 2023-12-10 15:01


NVD link : CVE-2021-3684

Mitre link : CVE-2021-3684

CVE.ORG link : CVE-2021-3684


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_assisted_installer
  • openshift_container_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File