PT-2019-11604 · Red Hat · Openshift Container Platform

Tatianab

·

Publicado

2019-07-30

·

Atualizado

2020-10-02

·

CVE-2019-10165

CVSS v3.1

2.3

Baixa

VetorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OpenShift Container Platform versions prior to 4.1.3
Description: The issue allows a user with sufficient privileges to recover OAuth tokens from audit logs for the Kubernetes API server and OpenShift API server. These tokens can then be used to access other resources.
Recommendations: For versions prior to 4.1.3, update to version 4.1.3 or later to resolve the issue.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10165

Produtos afetados

Openshift Container Platform