GHSA-mjqc-5c9x-xfcc

Suggest an improvement
Source
https://github.com/advisories/GHSA-mjqc-5c9x-xfcc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mjqc-5c9x-xfcc/GHSA-mjqc-5c9x-xfcc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mjqc-5c9x-xfcc
Withdrawn
2022-06-08T22:35:32Z
Published
2022-05-18T00:00:34Z
Modified
2022-06-08T22:35:32Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Duplicate advisory: Configuration exposure in github.com/coreos/ignition
Details

Duplicate Advisory

This advisory is a duplicate of GHSA-hj57-j5cw-2mwp. This link is preserved to maintain external references.

Original Description

A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.

Database specific
{
    "cwe_ids":  [
        "CWE-200",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-05-25T19:37:07Z",
    "nvd_published_at":  "2022-05-17T18:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/coreos/ignition/v2

Package

Name
github.com/coreos/ignition/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/coreos/ignition/v2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.14.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mjqc-5c9x-xfcc/GHSA-mjqc-5c9x-xfcc.json"