CVE-2021-3684
Summary
| CVE | CVE-2021-3684 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-24 20:15:00 UTC |
| Updated | 2023-04-03 17:56:00 UTC |
| Description | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user. |
Risk And Classification
Problem Types: CWE-532
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Application | Redhat | Openshift Assisted Installer | All | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MGMT-7450: Removing pull secret token from failure logs (#340) · openshift/assisted-installer@f3800cf · GitHub | MISC | github.com | |
| MGMT-7452: Remove token from assisted-installer-controller log (#338) · openshift/assisted-installer@2403dad · GitHub | MISC | github.com | |
| 1985962 – (CVE-2021-3684) CVE-2021-3684 assisted-installer: Image Pull Secret leaked through log files | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.