CVE-2021-20319
Last modified
CVE-2021-20319 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Coreos-Installer | < 0.10.1 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2011862Issue Tracking, Vendor Advisory
- https://github.com/coreos/coreos-installer/pull/659/commits/ad243c6f0eff2835b2da56ca5f7f33af76253c89Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2011862Issue Tracking, Vendor Advisory
- https://github.com/coreos/coreos-installer/pull/659/commits/ad243c6f0eff2835b2da56ca5f7f33af76253c89Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20319?
How severe is CVE-2021-20319?
How do I fix CVE-2021-20319?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20313A flaw was found in ImageMagick in versions before 7.0.11. A…7.5
- CVE-2021-20314Stack buffer overflow in libspf2 versions below 1.2.11 when …9.8
- CVE-2021-20315A locking protection bypass flaw was found in some versions …6.1
- CVE-2021-20316A flaw was found in the way Samba handled file/directory met…6.8
- CVE-2021-20317A flaw was found in the Linux kernel. A corrupted timer tree…4.4
- CVE-2021-20318The HornetQ component of Artemis in EAP 7 was not updated wi…7.2
- CVE-2021-2032Vulnerability in the MySQL Server product of Oracle MySQL (c…4.3
- CVE-2021-20320A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s3…5.5
- CVE-2021-20321A race condition accessing file object in the Linux kernel O…4.7
- CVE-2021-20322A flaw in the processing of received ICMP errors (ICMP fragm…7.4
- CVE-2021-20323A POST based reflected Cross Site Scripting vulnerability on…6.1
- CVE-2021-20324Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2021-20319?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
