CVE-2021-20319 - CVE House
Back to Database
Status published High CVE-2021-20319

An improper signature verification vulnerability was found in coreos-installer. A...

Vulnerability Description

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-20319

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

coreos-installer
Vulnerable Versions:
Affects coreos-installer before v0.10.1, Fixed in v0.10.1.

Timeline

Official Publish: March 4th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)