Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-1706

18
FAUCET Score

CVE-2022-1706 describes a vulnerability in Ignition configurations, specifically when running in unprivileged containers on VMware virtual machines, allowing access to Ignition configs containing secrets. This primarily affects various Fedora and Red Hat products, including Ignition and OpenShift Container Platform. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and requiring low privileges, leading to high confidentiality impact if secrets are present. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.14.0CPE matchmatch criteria
cpe:2.3:a:redhat:ignition:*:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.23%
Probability of exploitation in next 30 days
EPSS Percentile
66.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0123 is in the 80th percentile among its peer group of 21,951 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/coreos/ignition/v2Fixed in: 2.14.0
gopatch availablevia ghsa
Product: github.com/coreos/ignitionFixed in: 2.14.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ignition-0:2.14.0-1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.11Fixed in: ignition-0:2.14.0-3.rhaos4.11.el8
View patch
redhatvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

goGHSA-hj57-j5cw-2mwpmedium

Ignition config accessible to unprivileged software on VMware

May 25, 2022
redhatCVE-2022-1706Moderate

ignition: configs are accessible from unprivileged containers in VMs running on VMware products

May 4, 2022

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory
github.com / coreos/ignition/commit/4b70b44b430ecf8377a276e89b5acd3a6957d4ea
PatchThird Party Advisory
github.com / coreos/ignition/issues/1300
Third Party Advisory
github.com / coreos/ignition/issues/1315
Third Party Advisory
github.com / coreos/ignition/pull/1350
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/LY7LKGMQMXV6DGD263YQHNSLOJJ5VLV5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NP765L7TJI7CD4XVOHUWZVRYRH3FYBOR
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/T5QQXRGQKTN4YX2ZF3GQNEBDEOKJGCN3