PT-2019-5674 · Red Hat · Openshift Container Platform

Published

2019-10-07

·

Updated

2023-02-12

·

CVE-2019-14854

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenShift Container Platform 4
Description The issue is related to insufficient protection of log data. When the log level in an operator is set to Debug or higher, secret data written to static pod logs is not sanitized. This could allow a low-privileged user to read pod logs and discover secret material if a privileged user has already modified the log level in an operator. The vulnerability may enable a remote attacker to disclose protected information.
Recommendations For OpenShift Container Platform 4, consider setting the log level in operators to a level lower than Debug to minimize the risk of secret material exposure until a fix is available. As a temporary workaround, restrict access to pod logs to prevent low-privileged users from reading sensitive information.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2020-04971
CVE-2019-14854

Affected Products

Openshift Container Platform