Описание
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Affected | ||
Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Affected | ||
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Fixed | RHSA-2019:4052 | 16.12.2019 |
Red Hat OpenShift Container Platform 4.1 | openshift | Fixed | RHSA-2019:4087 | 17.12.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.4 Medium
CVSS3
Связанные уязвимости
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
The Kubernetes client-go library logs request headers at verbosity lev ...
Kubernetes client-go library logs may disclose credentials to unauthorized users
EPSS
4.4 Medium
CVSS3