CVE-2019-11250
29.08.2019, 01:15
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.Enginsight
Vendor | Product | Version |
---|---|---|
kubernetes | kubernetes | 𝑥 < 1.15.3 |
kubernetes | kubernetes | 1.15.3 |
kubernetes | kubernetes | 1.15.4:beta0 |
kubernetes | kubernetes | 1.16.0:alpha1 |
kubernetes | kubernetes | 1.16.0:alpha2 |
kubernetes | kubernetes | 1.16.0:alpha3 |
kubernetes | kubernetes | 1.16.0:beta1 |
kubernetes | kubernetes | 1.16.0:beta2 |
redhat | openshift_container_platform | 3.11 |
redhat | openshift_container_platform | 4.1 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
References