CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:redhat:openshift_assisted_installer:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-03-24 20:15

Updated : 2024-02-28 20:13


NVD link : CVE-2021-3684

Mitre link : CVE-2021-3684

CVE.ORG link : CVE-2021-3684


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_assisted_installer
  • openshift_container_platform
CWE
CWE-532

Insertion of Sensitive Information into Log File