CVE-2019-10165

Published
View on NVD ↗
CVSS v3
2.3
LOW
CVSS v2
2.1
LOW
Affected
2
PROJECTS

Description

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

The openshift-apiserver operator installs and maintains the openshift-apiserver on a cluster
GitHubGitHub
39
The kube-apiserver operator installs and maintains the kube-apiserver on a cluster
GitHubGitHub
84