First published: Sun Mar 07 2021(Updated: )
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gain additional access into noobaa deployment and can read/modify system configuration.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/noobaa-operator | <5.7.0 | 5.7.0 |
Redhat Noobaa-operator | <5.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3528 is a vulnerability found in NooBaa where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files.
The severity of CVE-2021-3528 is high with a CVSS score of 8.8.
CVE-2021-3528 affects noobaa-operator versions before 5.7.0.
An attacker with access to the log files could use the leaked AuthToken to gain additional access into the noobaa deployment and can read/modify data.
To fix CVE-2021-3528, update to version 5.7.0 of the noobaa-operator.