PT-2019-5674 · Red Hat · Openshift Container Platform

CVE-2019-14854

·

Publicado

2019-10-07

·

Atualizado

2023-02-12

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenShift Container Platform 4
Description The issue is related to insufficient protection of log data. When the log level in an operator is set to Debug or higher, secret data written to static pod logs is not sanitized. This could allow a low-privileged user to read pod logs and discover secret material if a privileged user has already modified the log level in an operator. The vulnerability may enable a remote attacker to disclose protected information.
Recommendations For OpenShift Container Platform 4, consider setting the log level in operators to a level lower than Debug to minimize the risk of secret material exposure until a fix is available. As a temporary workaround, restrict access to pod logs to prevent low-privileged users from reading sensitive information.

Exploit

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-04971
CVE-2019-14854

Produtos afetados

Openshift Container Platform