6.5
CVSSv3

CVE-2019-14854

Published: 07/01/2020 Updated: 12/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform 4.1

redhat openshift container platform 4.2

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 41 ose-cluster-kube-apiserver-operator-container security update Type/Severity Security Advisory: Moderate Topic An update for ose-cluster-kube-apiserver-operator-container is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security ...
Synopsis Moderate: OpenShift Container Platform 41 library-go security update Type/Severity Security Advisory: Moderate Topic An update for ose-cluster-kube-controller-manager-operator-container and ose-cluster-kube-scheduler-operator-container is now available for Red Hat OpenShift Container Platform 41 ...
Synopsis Moderate: OpenShift Container Platform 42 library-go security update Type/Severity Security Advisory: Moderate Topic An update for ose-cluster-kube-apiserver-operator-container and ose-cluster-kube-scheduler-operator-container is now available for Red Hat OpenShift Container Platform 42Red Hat P ...
Synopsis Moderate: OpenShift Container Platform 42 ose-cluster-kube-controller-manager-operator-container security update Type/Severity Security Advisory: Moderate Topic An update for ose-cluster-kube-controller-manager-operator-container is now available for Red Hat OpenShift Container Platform 42Red Ha ...
Impact: Moderate Public Date: 2019-10-07 CWE: CWE-117: Improper Output Neutralization for Logs Bugzilla: 1758953: ...