Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-19335

Опубликовано: 27 нояб. 2019
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

During installation of an OpenShift 4 cluster, the openshift-install command line tool creates an auth directory, with kubeconfig and kubeadmin-password files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-installer-artifactsAffected
Red Hat OpenShift Container Platform 4.2openshift4/ose-installerFixedRHSA-2020:046312.02.2020
Red Hat OpenShift Container Platform 4.2openshift4/ose-baremetal-installer-rhel7FixedRHSA-2020:047612.02.2020
Red Hat OpenShift Container Platform 4.2openshift4/ose-cli-artifactsFixedRHSA-2020:047612.02.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1777209openshift/installer: kubeconfig and kubeadmin-password are created with word-readable permissions

EPSS

Процентиль: 27%
0.00095
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
почти 6 лет назад

During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.

CVSS3: 4.4
github
больше 3 лет назад

During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.

EPSS

Процентиль: 27%
0.00095
Низкий

4.4 Medium

CVSS3