Описание
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | library-go | Not affected | ||
| Red Hat OpenShift Container Platform 3.11 | library-go | Not affected | ||
| Red Hat OpenShift Container Platform 3.9 | library-go | Not affected | ||
| Red Hat OpenShift Container Platform 4 | library-go | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-kube-controller-manager-operator | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-kube-scheduler-rhel9-operator | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-openshift-controller-manager-operator | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-svcat-controller-manager-operator | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-service-ca-operator | Affected | ||
| Red Hat OpenShift Container Platform 4.1 | openshift4/ose-console-operator | Fixed | RHSA-2019:2791 | 17.09.2019 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-117
https://bugzilla.redhat.com/show_bug.cgi?id=1734615openshift: Secret data written to pod logs when operator set at Debug level or higher
5.3 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
nvd
около 6 лет назад
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
CVSS3: 3.5
github
больше 4 лет назад
Sensitive Data Exposure in Openshift Container Platform
5.3 Medium
CVSS3