Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gc2p-g4fg-29vh

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Kubernetes did not effectively clear service account credentials

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()

Пакеты

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.12.0, < 1.12.5

1.12.5

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

>= 1.13.0, < 1.13.1

1.13.1

EPSS

Процентиль: 48%
0.00241
Низкий

8.1 High

CVSS3

Дефекты

CWE-212
CWE-271

Связанные уязвимости

CVSS3: 3.1
redhat
около 6 лет назад

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()

CVSS3: 8.1
nvd
около 6 лет назад

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not effectively clear service account credentials loaded using rest.InClusterConfig()

CVSS3: 8.1
debian
около 6 лет назад

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientCon ...

EPSS

Процентиль: 48%
0.00241
Низкий

8.1 High

CVSS3

Дефекты

CWE-212
CWE-271