6.5
CVSSv3

CVE-2019-10213

Published: 25/11/2019 Updated: 12/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift_container_platform 4.1

redhat openshift_container_platform 4.2

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 4116 container image security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-console-operator-container is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as ...
Synopsis Moderate: OpenShift Container Platform 41 operator security update Type/Severity Security Advisory: Moderate Topic An update for ose-cluster-authentication-operator-container, ose-cluster-config-operator-container, and ose-cluster-kube-apiserver-operator-container is now available for Red Hat Open ...
Synopsis Moderate: OpenShift Container Platform 41 ose-cluster-openshift-apiserver-operator-container security update Type/Severity Security Advisory: Moderate Topic An update for ose-cluster-openshift-apiserver-operator-container is now available for Red Hat OpenShift Container Platform 41Red Hat Produc ...