CVE-2019-10213

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

History

12 Feb 2023, 23:33

Type Values Removed Values Added
CWE CWE-532 CWE-117
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1734615', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1734615', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2019:2791', 'name': 'https://access.redhat.com/errata/RHSA-2019:2791', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2019-10213', 'name': 'https://access.redhat.com/security/cve/CVE-2019-10213', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2019-10213 openshift: Secret data written to pod logs when operator set at Debug level or higher OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

02 Feb 2023, 21:18

Type Values Removed Values Added
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1734615 -
  • (MISC) https://access.redhat.com/errata/RHSA-2019:2791 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2019-10213 -
Summary OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user. CVE-2019-10213 openshift: Secret data written to pod logs when operator set at Debug level or higher

Information

Published : 2019-11-25 15:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-10213

Mitre link : CVE-2019-10213

CVE.ORG link : CVE-2019-10213


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • openshift_container_platform
CWE
CWE-117

Improper Output Neutralization for Logs

CWE-532

Insertion of Sensitive Information into Log File