Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3675

Опубликовано: 03 нояб. 2022
Источник: nvd
CVSS3: 2.6
CVSS3: 5.5
EPSS Низкий

Описание

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any security fixes that have recently been applied to the machine. A password is still required to modify kernel command-line arguments and to access the GRUB command line.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:fedora_coreos:*:*:*:*:*:*:*:*
Версия от 36.20220820.3.0 (включая) до 37.20221031.1.0 (исключая)

EPSS

Процентиль: 15%
0.00049
Низкий

2.6 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-306

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any security fixes that have recently been applied to the machine. A password is still required to modify kernel command-line arguments and to access the GRUB command line.

EPSS

Процентиль: 15%
0.00049
Низкий

2.6 Low

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-306