Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11250

Опубликовано: 13 авг. 2019
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Edge Manager previewflightctlNot affected
Red Hat OpenShift Container Platform 3.10atomic-openshiftAffected
Red Hat OpenShift Container Platform 3.9atomic-openshiftAffected
Red Hat OpenShift Container Platform 3.11atomic-openshiftFixedRHSA-2019:405216.12.2019
Red Hat OpenShift Container Platform 4.1openshiftFixedRHSA-2019:408717.12.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1740434kubernetes: Bearer tokens written to logs at high verbosity levels (>= 7)

EPSS

Процентиль: 76%
0.01766
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
nvd
почти 7 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
debian
почти 7 лет назад

The Kubernetes client-go library logs request headers at verbosity lev ...

CVSS3: 6.5
github
около 4 лет назад

Kubernetes client-go library logs may disclose credentials to unauthorized users

EPSS

Процентиль: 76%
0.01766
Низкий

4.4 Medium

CVSS3