Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8xm-p2h4-v6jp

Опубликовано: 24 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

Пакеты

Наименование

github.com/openshift/assisted-installer

go
Затронутые версииВерсия исправления

< 1.0.25.1

1.0.25.1

EPSS

Процентиль: 16%
0.00052
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 3.3
redhat
больше 3 лет назад

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

CVSS3: 5.5
nvd
почти 3 года назад

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

EPSS

Процентиль: 16%
0.00052
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532