CVE-2019-14854

Related Vulnerabilities: CVE-2019-14854  

Impact: Moderate Public Date: 2019-10-07 CWE: CWE-117: Improper Output Neutralization for Logs Bugzilla: 1758953: CVE-2019-14854 library-go: Secret data written to static pod logs when operator set at Debug level or higher No description is available for this CVE.

No description is available for this CVE.

Find out more about CVE-2019-14854 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat OpenShift Container Platform 4.1 (ose-cluster-kube-apiserver-operator-container, ose-cluster-kube-controller-manager-operator-container, ose-cluster-kube-scheduler-operator-container):
This vulnerability is currently targeted to be addressed in an upcoming release.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact None
Availability Impact None