Low severity2.3NVD Advisory· Published Jul 30, 2019· Updated Jun 17, 2026
CVE-2019-10165
CVE-2019-10165
Description
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*range: <4.1.3
- (no CPE)range: <4.1.3
Patches
Vulnerability mechanics
References
3- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchVendor Advisory
- github.com/openshift/cluster-kube-apiserver-operator/pull/499/nvdPatchThird Party Advisory
- github.com/openshift/cluster-openshift-apiserver-operator/pull/205nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.