PT-2021-13884 · Unknown · Coreos-Installer

Bgilbert

+1

·

Published

2021-10-12

·

Updated

2022-03-11

·

CVE-2021-20319

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: coreos-installer versions prior to 0.10.1
Description: An improper signature verification issue was found in coreos-installer, allowing a specially crafted gzip installation image to bypass image signature verification. This can lead to the installation of unsigned content, enabling an attacker who can modify the original installation image to write arbitrary data and achieve full access to the node being installed. The issue affects installations using --image-file, --image-url, or coreos.inst.image url, as well as coreos-installer download --decompress --image-url when the hosting service is compromised or an active attacker gains control of the HTTPS response.
Recommendations: For versions prior to 0.10.1, update to coreos-installer version 0.10.1 to resolve the issue. As a temporary workaround, for coreos-installer download, do not use the -d or --decompress options. For coreos-installer install, manually inspect the stderr output, and if BAD signature appears, do not boot from the target disk.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20319
GHSA-3R3G-G73X-G593
RHSA-2021:3926
RHSA-2021:3930
RHSA-2021:3934
RHSA-2021:4008
RUSTSEC-2022-0103

Affected Products

Coreos-Installer