Back to search
CVE-2021-20319
Published: Mar 4, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.
| Vendor | Product | Versions |
|---|---|---|
n/a | coreos-installer | affected Affects coreos-installer before v0.10.1, Fixed in v0.10.1. |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now