VYPR

coreos-installer

by Red Hat

Source repositories

CVEs (2)

  • CVE-2021-3917MedAug 23, 2022
    risk 0.29cvss 5.5epss 0.00

    A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to…

  • CVE-2021-20319HigMar 4, 2022
    risk 0.00cvss 7.8epss 0.01

    An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original…