Inclusion of Sensitive Information in Log Files in Openshift assisted-installer - CVE-2021-3684
Published: October 31, 2022
Openshift assisted-installer
Red Hat Inc.
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to during generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. A local user can exploit this by re-using the image pull secret to pull container images from the registry as the associated user.