PT-2021-20870 · Unknown · Noobaa-Operator

Hardik Vyas

·

Published

2021-05-13

·

Updated

2022-10-27

·

CVE-2021-3528

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: noobaa-operator versions prior to 5.7.0
Description: A flaw was found in noobaa-operator where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gain additional access into noobaa deployment and can read/modify system configuration.
Recommendations: For versions prior to 5.7.0, update to version 5.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Fix

Insertion into Log File

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-3528

Affected Products

Noobaa-Operator