5.5
CVSSv3

CVE-2021-3684

Published: 24/03/2023 Updated: 03/04/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift_assisted_installer

redhat openshift_container_platform 4.6

Vendor Advisories

Description<!---->A vulnerability was found in OpenShift Assisted Installer During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated userA vulnerability was fo ...