PT-2019-11641 · Kubernetes · Kube-State-Metrics+1
Moritz S
·
Publicado
2019-11-05
·
Atualizado
2022-05-24
·
CVE-2019-10223
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
kube-state-metrics versions v1.7.0 through v1.7.1
Description:
A security issue was discovered in kube-state-metrics where an experimental feature added to versions v1.7.0 and v1.7.1 enabled annotations to be exposed as metrics. By default, kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default
kubectl behavior and this new feature can cause the entire secret content to end up in metric labels, thus inadvertently exposing the secret content in metrics.Recommendations:
For versions v1.7.0 and v1.7.1, upgrade to the v1.7.2 release as soon as possible. As a temporary workaround, consider disabling the experimental feature that exposes annotations as metrics until a patch is available. Restrict access to sensitive information in metric labels to minimize the risk of exploitation.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kube-State-Metrics
Kubectl