Unrated severityNVD Advisory· Published Jul 30, 2019· Updated Aug 4, 2024
CVE-2019-10165
CVE-2019-10165
Description
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: < 4.1.3
Patches
Vulnerability mechanics
References
3- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- github.com/openshift/cluster-kube-apiserver-operator/pull/499/mitrex_refsource_CONFIRM
- github.com/openshift/cluster-openshift-apiserver-operator/pull/205mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.