Unrated severityNVD Advisory· Published Mar 18, 2020· Updated Aug 5, 2024
CVE-2019-19335
CVE-2019-19335
Description
During installation of an OpenShift 4 cluster, the openshift-install command line tool creates an auth directory, with kubeconfig and kubeadmin-password files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: ose-installer as shipped in Openshift 4.2
Patches
Vulnerability mechanics
References
1- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.