Skip to content

Sensitive Data Exposure in Openshift Container Platform

Moderate severity Unreviewed Published May 17, 2021 to the GitHub Advisory Database • Updated Nov 12, 2023

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

References

Published by the National Vulnerability Database Nov 25, 2019
Published to the GitHub Advisory Database May 17, 2021
Last updated Nov 12, 2023

Severity

Moderate

EPSS score

0.108%
(45th percentile)

CVE ID

CVE-2019-10213

GHSA ID

GHSA-m2h6-jxj8-4jqf

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.