Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmrx-5g74-6v2f

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Kubernetes client-go library logs may disclose credentials to unauthorized users

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Пакеты

Наименование

k8s.io/client-go

go
Затронутые версииВерсия исправления

< 0.17.0

0.17.0

Наименование

k8s.io/kubernetes

go
Затронутые версииВерсия исправления

< 1.16.0-beta.1

1.16.0-beta.1

EPSS

Процентиль: 74%
0.00872
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 4.4
redhat
почти 6 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
nvd
почти 6 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
debian
почти 6 лет назад

The Kubernetes client-go library logs request headers at verbosity lev ...

EPSS

Процентиль: 74%
0.00872
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-532