PT-2021-20870 · Unknown · Noobaa-Operator
Hardik Vyas
·
Published
2021-05-13
·
Updated
2022-10-27
·
CVE-2021-3528
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
noobaa-operator versions prior to 5.7.0
Description:
A flaw was found in noobaa-operator where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gain additional access into noobaa deployment and can read/modify system configuration.
Recommendations:
For versions prior to 5.7.0, update to version 5.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.
Fix
Insertion into Log File
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Noobaa-Operator