Benjamin Gilbert

1 exploit Active since Aug 2022
CVE-2021-3917 WRITEUP MEDIUM WRITEUP
coreos-installer < 0.10.0 - Incorrect Default Permissions in Ignition Config
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
CVSS 5.5