Description
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
No analysis available yet.
Remediation
Vendor Workaround
lower log verbosity levels to <= 6
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4401 | Kubernetes client-go library logs may disclose credentials to unauthorized users |
Github GHSA |
GHSA-jmrx-5g74-6v2f | Kubernetes client-go library logs may disclose credentials to unauthorized users |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2024-09-17T02:06:55.457Z
Reserved: 2019-04-17T00:00:00.000Z
Link: CVE-2019-11250
No data.
Status : Modified
Published: 2019-08-29T01:15:11.523
Modified: 2024-11-21T04:20:48.343
Link: CVE-2019-11250
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA