CVE-2021-3344 is a high-severity privilege escalation flaw in OpenShift builder versions prior to v0.0.0-20210125201112-7901cb396121, affecting Red Hat OpenShift Container Platform. During the build process, credentials outside the build context are mounted into the container image, allowing an attacker with code execution privileges during build time to reuse these credentials. This can lead to overwriting arbitrary container images in internal registries, escalating privileges, and posing a high threat to data confidentiality, integrity, and system availability. With a CVSS score of 8.8 (HIGH), the vulnerability has a low attack complexity and requires low privileges, but there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2021-01-26CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_builder:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.5.33CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* | ||
>= 4.6, < 4.6.16CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.