CVE-2019-11250
Kubernetes client-go logs authorization headers at debug verbosity levels
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
La biblioteca de servicio de cliente de Kubernetes registra los encabezados de solicitud en niveles de detalle de 7 o superior. Esto puede revelar las credenciales a los usuarios no autorizados a través de los registros o la salida del comando. Los componentes de Kubernetes (como kube-apiserver) anteriores a v1.16.0, que utilizan la autenticación de token básica o portadora y se ejecutan en niveles de detalle elevados, se ven afectados.
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Issues addressed include a bypass vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-17 CVE Reserved
- 2019-08-29 CVE Published
- 2024-09-17 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2020/10/16/2 | Mailing List |
|
https://github.com/kubernetes/kubernetes/issues/81114 | Third Party Advisory | |
https://security.netapp.com/advisory/ntap-20190919-0003 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:4052 | 2020-10-16 | |
https://access.redhat.com/errata/RHSA-2019:4087 | 2020-10-16 | |
https://access.redhat.com/security/cve/CVE-2019-11250 | 2019-12-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1740434 | 2019-12-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | < 1.15.3 Search vendor "Kubernetes" for product "Kubernetes" and version " < 1.15.3" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.15.3 Search vendor "Kubernetes" for product "Kubernetes" and version "1.15.3" | - |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.15.4 Search vendor "Kubernetes" for product "Kubernetes" and version "1.15.4" | beta0 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | alpha1 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | alpha2 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | alpha3 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | beta1 |
Affected
| ||||||
Kubernetes Search vendor "Kubernetes" | Kubernetes Search vendor "Kubernetes" for product "Kubernetes" | 1.16.0 Search vendor "Kubernetes" for product "Kubernetes" and version "1.16.0" | beta2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 3.11 Search vendor "Redhat" for product "Openshift Container Platform" and version "3.11" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openshift Container Platform Search vendor "Redhat" for product "Openshift Container Platform" | 4.1 Search vendor "Redhat" for product "Openshift Container Platform" and version "4.1" | - |
Affected
|