Vulnerabilities > CVE-2019-10213 - Unspecified vulnerability in Redhat Openshift Container Platform 4.1/4.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
OS | 1 |
Redhat
advisories |
|
References
- https://access.redhat.com/errata/RHSA-2019:4082
- https://access.redhat.com/errata/RHSA-2019:4082
- https://access.redhat.com/errata/RHSA-2019:4088
- https://access.redhat.com/errata/RHSA-2019:4088
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10213
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10213