CVE-2021-3917

Published
View on NVD ↗
CVSS v3
5.5
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.

Issue tracker for Fedora CoreOS
GitHubGitHub
278
Installer for CoreOS disk images
GitHubGitHub
241