VYPR
Medium severity6.5NVD Advisory· Published Jan 7, 2020· Updated Jun 17, 2026

CVE-2019-14854

CVE-2019-14854

Description

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.2:*:*:*:*:*:*:*
    • (no CPE)range: 4
  • Red Hat/library-gov5
    Range: As shipped with Openshift 4.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.