Vulnerabilities > CVE-2019-10213 - Unspecified vulnerability in Redhat Openshift Container Platform 4.1/4.2

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
redhat

Summary

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

Redhat

advisories
  • rhsa
    idRHSA-2019:4082
  • rhsa
    idRHSA-2019:4088