CVE-2021-3684
MEDIUMRedhat Openshift Assisted Installer - Log Information Exposure
Title source: ruleDescription
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
References (3)
Core 3
Core References
Issue Tracking, Patch, Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1985962
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
34.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (3)
openshift/assisted-installer
0 - 1.0.25.1Go
redhat/openshift_assisted_installer
< 1.0.25.3
redhat/openshift_container_platform
4.6
Published
Mar 24, 2023
Tracked Since
Feb 18, 2026