PT-2021-13884 · Unknown · Coreos-Installer
Bgilbert
+1
·
Published
2021-10-12
·
Updated
2022-03-11
·
CVE-2021-20319
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
coreos-installer versions prior to 0.10.1
Description:
An improper signature verification issue was found in coreos-installer, allowing a specially crafted gzip installation image to bypass image signature verification. This can lead to the installation of unsigned content, enabling an attacker who can modify the original installation image to write arbitrary data and achieve full access to the node being installed. The issue affects installations using
--image-file, --image-url, or coreos.inst.image url, as well as coreos-installer download --decompress --image-url when the hosting service is compromised or an active attacker gains control of the HTTPS response.Recommendations:
For versions prior to 0.10.1, update to coreos-installer version 0.10.1 to resolve the issue.
As a temporary workaround, for
coreos-installer download, do not use the -d or --decompress options.
For coreos-installer install, manually inspect the stderr output, and if BAD signature appears, do not boot from the target disk.Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coreos-Installer