During installation of an OpenShift 4 cluster, the ...
Low severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 10, 2023
Description
Published by the National Vulnerability Database
Mar 18, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 10, 2023
During installation of an OpenShift 4 cluster, the
openshift-install
command line tool creates anauth
directory, withkubeconfig
andkubeadmin-password
files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.References