CVE-2021-3528
CVE-2021-3528
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 may 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gain additional access into noobaa deployment and can read/modify system configuration.
Productos afectados
n/a · NooBaa¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →