A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: redhat
Published: 2023-03-24T00:00:00.000Z
Updated: 2025-02-25T15:19:30.784Z
Reserved: 2021-08-05T00:00:00.000Z
Link: CVE-2021-3684

Updated: 2024-08-03T17:01:08.419Z

Status : Modified
Published: 2023-03-24T20:15:08.160
Modified: 2024-11-21T06:22:09.373
Link: CVE-2021-3684
