Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/openshift/assisted-installer
  4. ›
  5. CVE-2021-3684

CVE-2021-3684: OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs

March 24, 2023

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

References

  • bugzilla.redhat.com/show_bug.cgi?id=1985962
  • github.com/advisories/GHSA-g8xm-p2h4-v6jp
  • github.com/openshift/assisted-installer/commit/2403dad3795406f2c5d923af0894e07bc8b0bdc4
  • github.com/openshift/assisted-installer/commit/f3800cfa3d64ce6dcd6f7b73f0578bb99bfdaf7a
  • nvd.nist.gov/vuln/detail/CVE-2021-3684

Code Behaviors & Features

Detect and mitigate CVE-2021-3684 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.25.1

Fixed versions

  • v1.0.25.1

Solution

Upgrade to version 1.0.25.1 or above.

Impact 5.5 MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Source file

go/github.com/openshift/assisted-installer/CVE-2021-3684.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:07 +0000.