Rapid7 Vulnerability & Exploit Database

Red Hat OpenShift: CVE-2021-20319: coreos-installer: incorrect signature verification on gzip-compressed install images

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Red Hat OpenShift: CVE-2021-20319: coreos-installer: incorrect signature verification on gzip-compressed install images

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
10/28/2021
Created
10/29/2021
Added
10/28/2021
Modified
05/10/2023

Description

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.

Solution(s)

  • linuxrpm-upgrade-coreos-installer

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;