CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
- Redhat Ignition
- < 2.14.0
- Redhat Openshift Container Platform
- = 4.0
- Redhat Enterprise Linux
- = 9.0
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.3% (67th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2022-05-17
CVE-2022-1706 at NVD
No indexed exploits for CVE-2022-1706 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-1706 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.