6.5
CVSSv3

CVE-2019-11250

Published: 29/08/2019 Updated: 16/10/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes 1.16.0

kubernetes kubernetes

kubernetes kubernetes 1.15.4

kubernetes kubernetes 1.15.3

redhat openshift container platform 3.11

redhat openshift container platform 4.1

Vendor Advisories

Debian Bug report logs - #934801 kubernetes: CVE-2019-11250 Package: src:kubernetes; Maintainer for src:kubernetes is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 15 Aug 2019 05:33:02 UTC Severity: grave Tags: security, upstream Found in version kubernetes/17 ...
Synopsis Moderate: OpenShift Container Platform 311 atomic-openshift security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as having a security impact of Mo ...
Synopsis Moderate: OpenShift Container Platform 41 openshift security update Type/Severity Security Advisory: Moderate Topic An update for openshift is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Moderate A Common ...