Privilege Escalation Affecting coreos-installer package, versions <0.10.0


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-COREOSINSTALLER-1912890
  • published9 Nov 2021
  • disclosed8 Nov 2021
  • creditxlejo

Introduced: 8 Nov 2021

CVE-2021-3917  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade coreos-installer to version 0.10.0 or higher.

Overview

coreos-installer is a program to assist with installing Fedora CoreOS (FCOS) and Red Hat Enterprise Linux CoreOS (RHCOS).

Affected versions of this package are vulnerable to Privilege Escalation. The user-provided Ignition config was written to /boot/ignition/config.ign with world-readable permissions, granting unprivileged users access to any secrets included in the config.

CVSS Scores

version 3.1