VDB
CVE-2019-10213
CVE-2019-10213
PUBLISHED
CVSS 5.300000190734863 MEDIUM
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
EPSS 0.99% · 59.9th percentile
Risk Scores
CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.99%
59.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | openshift_container_platform | 4.2, 4.1 |
| Red Hat | openshift | versions Red Hat OpenShift 4.1 and Red Hat OpenShift 4.2 |
Timeline
- Nov 25, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10213 advisory
- https://github.com/openshift/library-go/pull/244 url
- https://github.com/openshift/library-go/pull/472 url
- https://access.redhat.com/errata/RHSA-2019:4088 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1734615 url
- https://access.redhat.com/errata/RHSA-2019:4082 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10213 issue