CVE-2019-10165
Published
CVSS v3
2.3
LOW
CVSS v2
2.1
LOW
Affected
2
PROJECTS
Description
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
The openshift-apiserver operator installs and maintains the openshift-apiserver on a cluster
The kube-apiserver operator installs and maintains the kube-apiserver on a cluster