VDB
CVE-2019-14854
CVE-2019-14854
PUBLISHED
CVSS 5.300000190734863 MEDIUM
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
EPSS 0.80% · 53.1th percentile
Risk Scores
CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.80%
53.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | library-go | As shipped with Openshift 4.x |
| redhat | openshift_container_platform | 4.1, 4.2 |
Timeline
- Jan 7, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14854 url
- https://nvd.nist.gov/vuln/detail/CVE-2019-14854 advisory
- https://access.redhat.com/errata/RHSA-2019:4075 url
- https://access.redhat.com/errata/RHSA-2019:4081 url
- https://access.redhat.com/errata/RHSA-2019:4091 url
- https://access.redhat.com/errata/RHSA-2019:4098 url
- https://access.redhat.com/security/cve/CVE-2019-14854 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1758953 url