{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "noobaa-operator leaking RPC AuthToken into log files",
    "tracking": {
      "current_release_date": "2026-08-11T14:55:33+00:00",
      "generator": {
        "date": "2026-08-11T14:55:33+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-3528",
      "initial_release_date": "2021-03-07T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:55:33+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Openshift Container Storage 4.6",
            "product": {
              "name": "Red Hat Openshift Container Storage 4.6",
              "product_id": "openshift-container-storage-4.6.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift_container_storage:4"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Openshift Container Storage 4.6",
            "product": {
              "name": "Red Hat Openshift Container Storage 4.6",
              "product_id": "openshift-container-storage-4.6::el8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift_container_storage:4.6::el8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Openshift Container Storage 4.7",
            "product": {
              "name": "Red Hat Openshift Container Storage 4.7",
              "product_id": "openshift-container-storage-4.7::el8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift_container_storage:4.7::el8"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ocs4/mcg-rhel8-operator",
            "product": {
              "name": "ocs4/mcg-rhel8-operator",
              "product_id": "ocs4/mcg-rhel8-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/mcg-rhel8-operator?repository_url=registry.redhat.io/ocs4/mcg-rhel8-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ocs4/mcg-rhel8-operator",
            "product": {
              "name": "ocs4/mcg-rhel8-operator",
              "product_id": "ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6",
              "product_identification_helper": {
                "purl": "pkg:oci/mcg-rhel8-operator@5.6.0-57.43b2f28.5.6?repository_url=registry.redhat.io/ocs4/mcg-rhel8-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ocs4/mcg-rhel8-operator",
            "product": {
              "name": "ocs4/mcg-rhel8-operator",
              "product_id": "ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7",
              "product_identification_helper": {
                "purl": "pkg:oci/mcg-rhel8-operator@5.7.0-69.85e2026.5.7?repository_url=registry.redhat.io/ocs4/mcg-rhel8-operator"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ocs4/mcg-rhel8-operator as a component of Red Hat Openshift Container Storage 4.6",
          "product_id": "openshift-container-storage-4.6.z:ocs4/mcg-rhel8-operator"
        },
        "product_reference": "ocs4/mcg-rhel8-operator",
        "relates_to_product_reference": "openshift-container-storage-4.6.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6 as a component of Red Hat Openshift Container Storage 4.6",
          "product_id": "openshift-container-storage-4.6::el8:ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6"
        },
        "product_reference": "ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6",
        "relates_to_product_reference": "openshift-container-storage-4.6::el8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7 as a component of Red Hat Openshift Container Storage 4.7",
          "product_id": "openshift-container-storage-4.7::el8:ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7"
        },
        "product_reference": "ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7",
        "relates_to_product_reference": "openshift-container-storage-4.7::el8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-3528",
      "cwe": {
        "id": "CWE-538",
        "name": "Insertion of Sensitive Information into Externally-Accessible File or Directory"
      },
      "discovery_date": "2021-03-10T00:00:00+00:00",
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in NooBaa, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files.  An attacker with access to the log files could use this AuthToken to gain additional access into noobaa deployment and can read/modify system configuration.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "openshift-container-storage-4.6::el8:ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6",
          "openshift-container-storage-4.7::el8:ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7"
        ],
        "known_affected": [
          "openshift-container-storage-4.6.z:ocs4/mcg-rhel8-operator"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-3528"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3528"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-3528"
        }
      ],
      "remediations": [
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "openshift-container-storage-4.6.z:ocs4/mcg-rhel8-operator"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2021-05-19T09:14:24+00:00",
          "details": "Apply advisory RHSA-2021:2041 as per vendors instructions.",
          "product_ids": [
            "openshift-container-storage-4.7::el8:ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:2041"
        },
        {
          "category": "vendor_fix",
          "date": "2021-06-17T15:46:37+00:00",
          "details": "Apply advisory RHSA-2021:2479 as per vendors instructions.",
          "product_ids": [
            "openshift-container-storage-4.6::el8:ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:2479"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 8.8,
            "baseSeverity": "HIGH"
          },
          "products": [
            "openshift-container-storage-4.6.z:ocs4/mcg-rhel8-operator",
            "openshift-container-storage-4.6::el8:ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6",
            "openshift-container-storage-4.7::el8:ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "openshift-container-storage-4.6.z:ocs4/mcg-rhel8-operator",
            "openshift-container-storage-4.6::el8:ocs4/mcg-rhel8-operator-0:5.6.0-57.43b2f28.5.6",
            "openshift-container-storage-4.7::el8:ocs4/mcg-rhel8-operator-0:5.7.0-69.85e2026.5.7"
          ]
        }
      ],
      "title": "noobaa-operator leaking RPC AuthToken into log files"
    }
  ]
}