← Back

CVE-2019-11250

nvd nist
Published: Aug 29, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Affected (10)

1 product
Kubernetes
1 product
Openshift Container Platform
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Kubernetes
Before 1.15.3
Version 1.15.3
Version 1.15.4 beta0
Version 1.16.0 alpha1
Version 1.16.0 alpha2
Version 1.16.0 alpha3
Version 1.16.0 beta1
Version 1.16.0 beta2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.11
Version 4.1

References (10)

Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: jordan@liggitt.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.