2.1
CVSSv2

CVE-2019-10165

Published: 30/07/2019 Updated: 02/10/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 2.3 | Impact Score: 1.4 | Exploitability Score: 0.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform

Vendor Advisories

Synopsis Low: OpenShift Container Platform 41 image security update Type/Severity Security Advisory: Low Topic An update for ose-cluster-kube-apiserver-operator-container andose-cluster-openshift-apiserver-operator-container is now available for RedHat OpenShift Container Platform 41Red Hat Product Secur ...