ZeroHour

CVE-2021-3684

CVSS 3.1
5.5 medium
EPSS
<1%p16
Published
()
Modified
Description

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

Vendors
redhat
Products
openshift assisted installer, openshift container platform
Weakness
CWE-532
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.