CRITICALcrates.io →
coreos-installer improperly verifies GPG signature when decompressing gzipped artifact
coreos-installer improperly verifies GPG signature when decompressing gzipped artifact
Affected packages
- coreos-installer
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/coreos/coreos-installer/security/advisories/GHSA-3r3g-g73x-g593
- https://nvd.nist.gov/vuln/detail/CVE-2021-20319
- https://github.com/coreos/coreos-installer/pull/655
- https://github.com/coreos/coreos-installer/pull/659/commits/ad243c6f0eff2835b2da56ca5f7f33af76253c89
- https://bugzilla.redhat.com/show_bug.cgi?id=2011862
- https://github.com/coreos/coreos-installer
- https://rustsec.org/advisories/RUSTSEC-2022-0103.html
Structured record: https://osv.dev/vulnerability/GHSA-3r3g-g73x-g593
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta