MEDIUM6.5
GHSA-jmrx-5g74-6v2f
Kubernetes client-go library logs may disclose credentials to unauthorized users
Quick fix
GHSA-jmrx-5g74-6v2f — k8s.io/client-go: upgrade to the fixed version with the command below.
go get k8s.io/client-go@v0.17.0Details
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/kubernetes
Introduced in:
0Fixed in: 1.16.0-beta.1Fix
go get k8s.io/kubernetes@v1.16.0-beta.1References
- https://nvd.nist.gov/vuln/detail/CVE-2019-11250[ADVISORY]
- https://github.com/kubernetes/kubernetes/issues/81114[WEB]
- https://github.com/kubernetes/kubernetes/pull/81330[WEB]
- https://github.com/kubernetes/kubernetes/commit/4441f1d9c3e94d9a3d93b4f184a591cab02a5245[WEB]
- https://access.redhat.com/errata/RHSA-2019:4052[WEB]
- https://access.redhat.com/errata/RHSA-2019:4087[WEB]
- https://github.com/kubernetes/kubernetes[PACKAGE]
- https://pkg.go.dev/vuln/GO-2021-0065[WEB]
- https://security.netapp.com/advisory/ntap-20190919-0003[WEB]
- http://www.openwall.com/lists/oss-security/2020/10/16/2[WEB]