CVE-2019-11250
Kubernetes client-go logs authorization headers at debug verbosity levels
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
La biblioteca de servicio de cliente de Kubernetes registra los encabezados de solicitud en niveles de detalle de 7 o superior. Esto puede revelar las credenciales a los usuarios no autorizados a través de los registros o la salida del comando. Los componentes de Kubernetes (como kube-apiserver) anteriores a v1.16.0, que utilizan la autenticación de token básica o portadora y se ejecutan en niveles de detalle elevados, se ven afectados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-17 CVE Reserved
- 2019-08-29 CVE Published
- 2024-08-05 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2020/10/16/2 | Mailing List | |
https://github.com/kubernetes/kubernetes/issues/81114 | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20190919-0003 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:4052 | 2020-10-16 | |
https://access.redhat.com/errata/RHSA-2019:4087 | 2020-10-16 | |
https://access.redhat.com/security/cve/CVE-2019-11250 | 2019-12-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1740434 | 2019-12-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | < 1.15.3 Search vendor "Kubernetes" for product "Kubernetes" and version " < 1.15.3" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.15.3 Search vendor "Kubernetes" for product "Kubernetes" and version "1.15.3" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.15.4 Search vendor "Kubernetes" for product "Kubernetes" and version "1.15.4" | beta0 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | alpha1 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | alpha2 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | alpha3 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | beta1 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | beta2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 3.11 Search vendor "Redhat" for product "Openshift Container Platform" and version "3.11" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 4.1 Search vendor "Redhat" for product "Openshift Container Platform" and version "4.1" | - |
Affected
|