187
VMScore

CVE-2019-19335

Published: 18/03/2020 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 4.2

redhat openshift 4.0

Vendor Advisories

Synopsis Low: OpenShift Container Platform 4218 ose-baremetal-installer-container and ose-cli-artifacts-container security update Type/Severity Security Advisory: Low Topic An update for ose-baremetal-installer-container and ose-cli-artifacts-container is now available for Red Hat OpenShift Container Plat ...
Synopsis Low: OpenShift Container Platform 4218 ose-installer-container security update Type/Severity Security Advisory: Low Topic An update for ose-installer-container is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has rated this update as having a security impact ...