CVE-2021-20319
Last modified
CVE-2021-20319 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Coreos-Installer | < 0.10.1 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2011862Issue Tracking, Vendor Advisory
- https://github.com/coreos/coreos-installer/pull/659/commits/ad243c6f0eff2835b2da56ca5f7f33af76253c89Patch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2011862Issue Tracking, Vendor Advisory
- https://github.com/coreos/coreos-installer/pull/659/commits/ad243c6f0eff2835b2da56ca5f7f33af76253c89Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20319?
How severe is CVE-2021-20319?
How do I fix CVE-2021-20319?
Are you affected by CVE-2021-20319?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
