GHSA-g8xm-p2h4-v6jp

Suggest an improvement
Source
https://github.com/advisories/GHSA-g8xm-p2h4-v6jp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-g8xm-p2h4-v6jp/GHSA-g8xm-p2h4-v6jp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g8xm-p2h4-v6jp
Aliases
Published
2023-03-24T21:30:48Z
Modified
2026-09-10T03:50:08Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs
Details

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.

Database specific
{
    "cwe_ids":  [
        "CWE-532"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-03-24T21:59:18Z",
    "nvd_published_at":  "2023-03-24T20:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/openshift/assisted-installer

Package

Name
github.com/openshift/assisted-installer
View open source insights on deps.dev
Purl
pkg:golang/github.com/openshift/assisted-installer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.25.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-g8xm-p2h4-v6jp/GHSA-g8xm-p2h4-v6jp.json"