coreos-installer did not have sufficiently restrictive permissions on directories /boot/ignition{,/config.ign}. A local attacker could use this flaw to have read access to potentially sensitive data. Upstream fix : https://github.com/coreos/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0c Fixed in version 0.10.0
Created rust-coreos-installer tracking bugs for this issue: Affects: fedora-all [bug 2018889]
Setting OSD "notaffected" per https://bugzilla.redhat.com/show_bug.cgi?id=1989544#c3
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.8 Via RHSA-2021:4829 https://access.redhat.com/errata/RHSA-2021:4829
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-3917