Inclusion of Sensitive Information in Log Files in Openshift assisted-installer - CVE-2021-3684
Published: October 31, 2022
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to during generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. A local user can exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Affected software
OpenShift Container Platform Assisted
How to mitigate CVE-2021-3684
OpenShift Container Platform Assisted - update to 1.0.25