CVE detail
CVE-2021-20319 — CVE-2021-20319
Published 2022-03-04 · Modified 2026-06-17 · Vendor redhat · Product coreos-installer · Source nvd
HIGH
severity
CVSS-derived band
0.0052
EPSS probability
exploitation probability, 30d
42.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References