Vulnerability Name: | CVE-2022-1706 (CCN-226852) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2022-05-04 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2022-05-04 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2022-10-11 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L/E:U/RL:O/RC:C)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-863 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-1706 Source: CCN Type: Red Hat Bugzilla - Bug 2082274 (CVE-2022-1706) - CVE-2022-1706 ignition: configs are accessible from unprivileged containers in VMs running on VMware products Source: MISC Type: Issue Tracking, Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=2082274 Source: XF Type: UNKNOWN ignition-cve20221706-info-disc(226852) Source: MISC Type: Patch, Third Party Advisory https://github.com/coreos/ignition/commit/4b70b44b430ecf8377a276e89b5acd3a6957d4ea Source: CCN Type: Ignition GIT Repository Security when using vmware to store the ignition config? #1300 Source: MISC Type: Third Party Advisory https://github.com/coreos/ignition/issues/1300 Source: MISC Type: Third Party Advisory https://github.com/coreos/ignition/issues/1315 Source: MISC Type: Third Party Advisory https://github.com/coreos/ignition/pull/1350 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-7846cac830 Source: FEDORA Type: Mailing List, Patch, Third Party Advisory FEDORA-2022-393948cc9e Source: FEDORA Type: Mailing List, Patch, Third Party Advisory FEDORA-2022-5df5dc8ec5 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: ![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |