Описание
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | library-go | Affected | ||
| Red Hat OpenShift Container Platform 4.1 | openshift4/ose-cluster-kube-apiserver-operator | Fixed | RHSA-2019:4081 | 04.12.2019 |
| Red Hat OpenShift Container Platform 4.1 | openshift4/ose-cluster-kube-controller-manager-operator | Fixed | RHSA-2019:4091 | 17.12.2019 |
| Red Hat OpenShift Container Platform 4.1 | openshift4/ose-cluster-kube-scheduler-operator | Fixed | RHSA-2019:4091 | 17.12.2019 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-cluster-kube-apiserver-operator | Fixed | RHSA-2019:4075 | 03.12.2019 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-cluster-kube-scheduler-operator | Fixed | RHSA-2019:4075 | 03.12.2019 |
| Red Hat OpenShift Container Platform 4.2 | openshift4/ose-cluster-kube-controller-manager-operator | Fixed | RHSA-2019:4098 | 11.12.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Уязвимость корпоративной платформы Red Hat OpenShift Container Platform, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.3 Medium
CVSS3