VulnerabilityModified
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products.
MEDIUM 6.5EPSS 1.27%
Does this matter?
Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- redhat/ignition · redhat/openshift container platform · redhat/enterprise linux · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2082274Issue Tracking, Vendor Advisory
- https://github.com/coreos/ignition/commit/4b70b44b430ecf8377a276e89b5acd3a6957d4eaPatch, Third Party Advisory
- https://github.com/coreos/ignition/issues/1300Third Party Advisory
- https://github.com/coreos/ignition/issues/1315Third Party Advisory
- https://github.com/coreos/ignition/pull/1350Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LY7LKGMQMXV6DGD263YQHNSLOJJ5VLV5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NP765L7TJI7CD4XVOHUWZVRYRH3FYBOR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5QQXRGQKTN4YX2ZF3GQNEBDEOKJGCN3/
- https://bugzilla.redhat.com/show_bug.cgi?id=2082274Issue Tracking, Vendor Advisory
- https://github.com/coreos/ignition/commit/4b70b44b430ecf8377a276e89b5acd3a6957d4eaPatch, Third Party Advisory
- https://github.com/coreos/ignition/issues/1300Third Party Advisory
- https://github.com/coreos/ignition/issues/1315Third Party Advisory
- https://github.com/coreos/ignition/pull/1350Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LY7LKGMQMXV6DGD263YQHNSLOJJ5VLV5/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NP765L7TJI7CD4XVOHUWZVRYRH3FYBOR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5QQXRGQKTN4YX2ZF3GQNEBDEOKJGCN3/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.