{"id":"CVE-2021-3917","aliases":["GHSA-862g-9h5m-m3qv"],"url":"https://o3.security/vulnerability/CVE-2021-3917","summary":"coreos-installer < 0.10.0 writes world-readable Ignition config to installed system","details":"A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.","published":"2022-08-23T20:15:08.360Z","modified":"2026-07-08T22:14:04.769240Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"coreos-installer","fixedVersion":"0.10.0"}],"fix":{"url":"https://github.com/coreos/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0c","label":"coreos/coreos-installer@2a36405"},"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2018478"},{"type":"FIX","url":"https://access.redhat.com/security/cve/CVE-2021-3917"},{"type":"FIX","url":"https://github.com/coreos/coreos-installer/commit/2a36405339c87b16ed6c76e91ad5b76638fbdb0c"},{"type":"FIX","url":"https://github.com/coreos/fedora-coreos-tracker/issues/889"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T22:14:04.769240Z"}}