CVE-2022-3675

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
03/11/2022
Last modified:
07/11/2023

Description

Fedora CoreOS supports setting a GRUB bootloader password<br /> using a Butane config. When this feature is enabled, GRUB requires a password to access the<br /> GRUB command-line, modify kernel command-line arguments, or boot<br /> non-default OSTree deployments. Recent Fedora CoreOS releases have a<br /> misconfiguration which allows booting non-default OSTree deployments<br /> without entering a password. This allows someone with access to the<br /> GRUB menu to boot into an older version of Fedora CoreOS, reverting<br /> any security fixes that have recently been applied to the machine. A<br /> password is still required to modify kernel command-line arguments and<br /> to access the GRUB command line.<br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:fedora_coreos:*:*:*:*:*:*:*:* 36.20220820.3.0 (including) 37.20221031.1.0 (excluding)