CVE Database
/

CVE-2021-3684

Back to search

CVE-2021-3684

Published: Mar 24, 2023

Modified: Feb 25, 2025

PUBLISHED

Description

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

VendorProductVersions

n/a

assisted-installer

affected
openshift/assisted-installer 1.0.25.1, openshift/assisted-installer 2.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now