A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/coreos/fedora-coreos-tracker/issues/889 | patch third party advisory issue tracking |
https://github.com/coreos/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0c | third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=2018478 | vendor advisory issue tracking |
https://access.redhat.com/security/cve/CVE-2021-3917 | patch vendor advisory |