First published: Fri Oct 29 2021(Updated: )
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/coreos-installer | <0.10.0 | 0.10.0 |
Redhat Coreos-installer | <0.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-3917 is high due to its impact on data confidentiality.
To fix CVE-2021-3917, upgrade the coreos-installer to version 0.10.1 or later.
CVE-2021-3917 affects users of the coreos-installer up to version 0.10.0.
CVE-2021-3917 is a local privilege escalation vulnerability that allows unauthorized access to sensitive data.
No, CVE-2021-3917 requires local access to the system to exploit the vulnerability.